Helpy.Io maintains a customer-support and help-desk platform focused on a narrowly scoped product line, with its vulnerability surface concentrated in web-based input handling and cross-site scripting concerns typical of interactive support applications. The observed weakness classes reflect the common challenges of sanitizing and validating user-supplied content in web forms and support ticket systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Helpy.Io over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20851HIGH Helpy before 2.2.0 allows agents to edit admins. | Jul 10, 2019 | 8.8 | 25 | NO | NO |
CVE-2026-40230MEDIUM Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist ar | Apr 29, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-40229MEDIUM Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it | Apr 29, 2026 | 5.4 | 23 | NO | NO |
CVE-2025-52184MEDIUM Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion. | Aug 26, 2025 | 6.1 | 21 | NO | NO |
CVE-2018-18886MEDIUM Helpy v2.1.0 has Stored XSS via the Ticket title. | Jun 18, 2019 | 6.1 | 20 | NO | NO |
CVE-2023-0357MEDIUM Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the | Apr 4, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Helpy.Io.
Media articles that mention a CVE ID that affects a product developed by Helpy.Io — matched by CVE ID, not by vendor name.