CVE-2026-77615
Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- CWE
- CWE-79
- Published
- 2026-09-17
- Last modified
- 2026-09-17
Affected products
- opencast opencast
- opencast opencast
- polimediaupv paella-player
Weakness type
Related vulnerabilities
- CVE-2026-78252 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-90943 — parallax filament-comments through 3.0.0 Stored XSS via Comment Body
- CVE-2026-90561 — Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
- CVE-2026-89256 — AVideo Bookmark Plugin Stored XSS via Chapter Names
- CVE-2026-89255 — AVideo LoginControl Stored XSS via PGP Public Key
- CVE-2026-15639 — Reflected Cross-Site Scripting
- CVE-2026-45143 — Chamilo LMS: Student-to-admin stored XSS in private messages via v-html
- CVE-2026-63459 — Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions