CVE-2025-47828
Executive Summary
CVE-2025-47828 affects Lumi H5P-Nodejs-library versions prior to 9.3.3. The library fails to invoke sanitizeHtml on plain text strings, allowing malicious content to be rendered without sanitization. This omission can lead to cross‑site scripting (XSS) attacks when user‑supplied text is displayed in a web context, potentially compromising user data and session integrity. The vulnerability is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 6.4 (MEDIUM) - Published: 2025-05-11T03:15:23.533 - Last Modified: 2026-09-27T06:16:49.573
Original Description: Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.
"Edison failed 10,000 times before he made the electric light. Do not be discouraged if you fail a few times."
— Napoleon Hill