SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2025-7062

MEDIUM · CVSS 5.2 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The H5P module `h5p-nodejs-library` is vulnerable to a stored cross-site scripting (XSS) flaw, allowing attackers to upload H5P content containing malicious JavaScript. When other users access this content, the injected script executes in their browsers, potentially compromising their sessions or data. Organizations utilizing this library, particularly those managing user-generated content, should prioritize addressing this vulnerability to safeguard their users.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-7062
Severity
MEDIUM
CVSS
5.2
EPSS
0.25%
Java

Original NVD Description

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.