A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.
History

Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.
Title Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
Weaknesses CWE-20
CWE-79
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SCHUTZWERK

Published: 2026-09-09T06:14:22.143Z

Updated: 2026-09-09T20:51:32.652Z

Reserved: 2025-07-04T06:13:06.914Z

Link: CVE-2025-7062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T07:16:55.180

Modified: 2026-09-09T21:17:01.127

Link: CVE-2025-7062

cve-icon Redhat

No data.