Back

HIGH

Paella Player: Stored XSS via caption cue text

Published Sep 17, 2026

Description

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 17, 2026
Updated Sep 22, 2026
Reserved Aug 20, 2026
CISA Vulnrichment
Updated Sep 22, 2026
NVD
Status Received
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-M6C8-JCW2-5R25