CVE-2025-7062

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 07:16

Updated : 2026-09-09 21:17


NVD link : CVE-2025-7062

Mitre link : CVE-2025-7062

CVE.ORG link : CVE-2025-7062


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')