CVE-2025-7062

    Dashboard / Vulnerabilities / CVE-2025-7062

    CVE-2025-7062

    Published: 9 Sept 2026Last Modified: 11 Sept 2026

    Summary: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education

    Details: A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v10.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2025-7062 | CVE-DB