PT-2026-83841 · Joomla · Helix Ultimate

CVE-2026-78077

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Helix Ultimate versions prior to 2.2.10
Description Stored Cross-Site Scripting (XSS) exists in the MegaMenu Layout Container and Embed Inputs. Unsanitized column and item configuration values stored within the MegaMenu layout JSON are rendered without complete contextual escaping, which allows the injection of malicious HTML or JavaScript. This was addressed by implementing stricter sanitization and tag allowlists using InputFilter and htmlspecialchars.
Recommendations Update Helix Ultimate to version 2.2.10 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78077

Affected Products

Helix Ultimate