CVE-2025-7062

Source
https://cve.org/CVERecord?id=CVE-2025-7062
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7062.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-7062
Published
2026-09-09T06:14:22Z
Modified
2026-09-11T03:48:22Z
Severity
  • 5.2 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:P CVSS Calculator
Summary
Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
Details

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module h5p-nodejs-library by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.

Database specific
{
    "cna_assigner": "SCHUTZWERK",
    "cwe_ids": [
        "CWE-20",
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7062.json"
}
References

Affected packages

Git / github.com/lumieducation/h5p-nodejs-library

Affected ranges

Type
GIT
Repo
https://github.com/lumieducation/h5p-nodejs-library
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "10.0.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.10.0
v0.10.1
v0.10.10
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.11.0
v0.11.1
v0.11.2
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.8.1
v0.9.0
v1.*
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v10.*
v10.0.0
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.2.0
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.4.0
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.1.0
v4.1.1
v4.1.2
v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.0.3
v6.0.4
v6.0.5
v6.0.6
v6.1.0
v6.1.1
v6.1.2
v6.1.3
v6.2.0
v7.*
v7.1.0
v7.3.0
v7.3.1
v8.*
v8.0.0
v8.1.5
v9.*
v9.0.5
v9.0.6
v9.0.9
v9.1.0
v9.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7062.json"