VYPR

html5lib

by Kaltura

CVEs (2)

  • CVE-2026-19912CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.01

    The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to…

  • CVE-2026-19913HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.00

    The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://.…