CVE-2025-47828: Lumi h5p-Node.js-Library

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.

Affected products

  • Lumi h5p-Node.js-Library: before 9.3.3 (fixed in 9.3.3)

Published 2025-05-11. Last modified 2026-09-27.