CVE-2025-47828 Details
Description
Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.
A vulnerability exists in Lumi H5P-Nodejs-library versions prior to 9.3.3, where the library fails to properly sanitize plain text strings. This oversight could potentially lead to the injection of unfiltered HTML, which may be exploited in various ways, depending on the context in which the unsanitized data is used.
Users can upgrade to Lumi H5P-Nodejs-library version 9.3.3 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2025CISA-ADP
Assessed May 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2026/Sep/69 | CVE | |
| https://github.com/Lumieducation/H5P-Nodejs-library/compare/v9.3.2...v9.3.3 | [email protected] | Release NotesVendor |
| https://github.com/Lumieducation/H5P-Nodejs-library/pull/3894 | [email protected] | Issue TrackingVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Lumi H5P-Nodejs-library | < 9.3.3 (semver) |
CPE
Remediation
| |
| @lumieducation/h5p-express | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-html-exporter | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-mongos3 | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-redis-lock | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-react | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-rest-example-client | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-rest-example-server | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-server | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-shared-state-server | All versions |
CPE
Remediation
| |
| @lumieducation/h5p-webcomponents | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | CVE Modified | [email protected] |
| Sep 27, 2026 | CVE Modified | CVE |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2025 | New CVE Received | [email protected] |
Volerion