---
id: CVE-2025-7062
title: >-
  A stored cross-site scripting (XSS) vulnerability has been identified in the
  H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and
  including 10.0.4
summary: >-
  A stored cross-site scripting (XSS) vulnerability has been identified in the
  H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and
  including 10.0.4. The library allows users to upload H5P content that contains
  malici…
severity: medium
cvss: 5.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:P'
cwe:
  - CWE-20
  - CWE-79
vendor: Lumi Education UG
product: h5p-nodejs-library
affected:
  - h5p-nodejs-library < 10.0.4
published: '2026-09-09'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:16:40.567'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7062'
references:
  - url: 'https://github.com/Lumieducation/H5P-Nodejs-library/releases/tag/v10.0.4'
    label: 23637b5d-af4c-4cf9-b8f6-deb7fd0f8423
  - url: 'https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-007/'
    label: 23637b5d-af4c-4cf9-b8f6-deb7fd0f8423
  - url: 'http://seclists.org/fulldisclosure/2026/Sep/41'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T20:30:55.655255Z'
cvssSource: cna
epss: 0.003
epssPercentile: 0.20216
ingestedAt: '2026-09-09T07:40:36.405Z'
---

## Overview

A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
