VYPR

Mwembed

by Kaltura

CVEs (4)

  • CVE-2026-19913Aug 25, 2026
    risk 0.00cvss epss

    The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://.…

  • CVE-2026-19912Aug 25, 2026
    risk 0.00cvss epss

    The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to…

  • CVE-2022-4882LowJan 9, 2023
    risk 0.00cvss 2.6epss 0.01

    A vulnerability was found in kaltura mwEmbed up to 2.91. It has been rated as problematic. Affected by this issue is some unknown functionality of the file modules/KalturaSupport/components/share/share.js of the component Share Plugin. The manipulation of the argument res leads…

  • CVE-2022-4876LowJan 4, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Kaltura mwEmbed up to 2.96.rc1 and classified as problematic. This issue affects some unknown processing of the file includes/DefaultSettings.php. The manipulation of the argument HTTP_X_FORWARDED_HOST leads to cross site scripting. The attack may be…