๐Ÿ” CVE Alert

CVE-2026-77615

HIGH 8.7

Paella Player: Stored XSS via caption cue text

CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
0th

Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.

CWE CWE-79
Vendor opencast
Product opencast
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for opencast opencast

Be the first to know when new high vulnerabilities affecting opencast opencast are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

opencast / opencast
< 19.7 >= 20.0, < 20.2
polimediaupv / paella-player
< 2.12.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25 github.com: https://github.com/opencast/opencast/pull/7736 github.com: https://github.com/opencast/opencast/commit/701682c635f668228c3e8fb7b4564b3294788e40 github.com: https://github.com/polimediaupv/paella-core/commit/94a36490808ac5a1f60a0745d71ec9253f6d206b github.com: https://github.com/polimediaupv/paella-core/commit/9b2f14ec4cf55efaf4c045c77a5ed8f5ec559ab4 github.com: https://github.com/polimediaupv/paella-player/commit/6fe4af7306044198c8e91e2e7f4128428b83cf03 github.com: https://github.com/opencast/opencast/releases/tag/19.7 github.com: https://github.com/opencast/opencast/releases/tag/20.2 github.com: https://github.com/polimediaupv/paella-player/blob/a1b6c42467938a00a4b4d0b8c68435cd4f9d2a16/repos/paella-core/CHANGELOG.md?plain=1#L21