Junglewise Threat Intelligence

CVE-2026-57829: JoomShaper Helix Ultimate unauthenticated stored XSS

CVE-2026-57829 · Severity: info · CVSS 8.7 · Published 2026-07-13

Technologies: JoomShaper Helix Ultimate. Vendors: JoomShaper.

Executive brief

Helix Ultimate, a popular framework and template for Joomla websites, contains a security vulnerability that allows unauthorized attackers to inject malicious scripts into the site. If exploited, these scripts are stored on the server and execute in the browsers of other users, potentially leading to account takeover, data theft, or website defacement. This issue affects a wide range of websites using this template for business, e-commerce, and portfolio purposes.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the JoomShaper Helix Ultimate extension for Joomla (versions 1.0 through 2.2.6). The flaw allows an unauthenticated remote attacker to inject malicious JavaScript into the application, which is then persistently stored and served to other users. The attack requires minimal user interaction (viewing the affected page) and can lead to full compromise of the user's session or administrative actions if a privileged user views the injected content. The vulnerability is addressed in version 2.2.8.

Affected products

  • joomshaper.com Helix Ultimate extension for Joomla 1.0-2.2.6

Timeline

  • 2026-07-07: patched: Version 2.2.8 released
  • 2026-07-13: advisory: CVE-2026-57829 published

References

Related threats