opencast vulnerabilities
CVEs whose affected-version data names the opencast package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-77615High· 8.7PoCPaella Player is a set of libraries to create a multi stream video player
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…
▾ Midnightopencast · opencastEPSS 0.39%via NVD
CVE-2026-77614High· 8.8PoCOpencast is a free, open-source platform to support the management of educational audio and video content
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected J…
▾ Midnightopencast · opencastEPSS 0.40%via NVD