CVE-2025-7062: Lumi Education Ug h5p-Node.js-Library
Medium severity, CVSS 5.2. EPSS: 0.3% chance of exploitation in the next 30 days.
A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.
Affected products
- Lumi Education Ug h5p-Node.js-Library: before 10.0.4 (fixed in 10.0.4)
Published 2026-09-09. Last modified 2026-09-22.