PT-2026-83841 · Joomla · Helix Ultimate
CVE-2026-78077
·
Published
2026-08-31
·
Updated
2026-08-31
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Helix Ultimate versions prior to 2.2.10
Description
Stored Cross-Site Scripting (XSS) exists in the MegaMenu Layout Container and Embed Inputs. Unsanitized column and item configuration values stored within the MegaMenu layout JSON are rendered without complete contextual escaping, which allows the injection of malicious HTML or JavaScript. This was addressed by implementing stricter sanitization and tag allowlists using
InputFilter and htmlspecialchars.Recommendations
Update Helix Ultimate to version 2.2.10 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helix Ultimate