CVE-2026-57829: Ollyo Helix Ultimate

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

Affected products

  • Ollyo Helix Ultimate: from 1.0, up to and including 2.2.6

Published 2026-07-13. Last modified 2026-07-23.