{"id":"CVE-2025-47828","title":"Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.","summary":"Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"Lumi","product":"H5P-Nodejs-library","affected":["H5P-Nodejs-library < 9.3.3"],"published":"2025-05-11","updated":"2026-09-27","sourceUpdated":"2026-09-27T06:16:49.573","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-47828","references":[{"url":"https://github.com/Lumieducation/H5P-Nodejs-library/compare/v9.3.2...v9.3.3","label":"cve@mitre.org"},{"url":"https://github.com/Lumieducation/H5P-Nodejs-library/pull/3894","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2026/Sep/69","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.00238,"epssPercentile":0.13308,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-05-12T14:38:37.073090Z"},"ingestedAt":"2026-09-27T05:43:09.225Z","slug":"CVE-2025-47828","body":"## Overview\n\nLumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}