CVE Watchtower

← Back to CVE List

CVE-2026-77615NVD

Description

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
Severity Level
HIGH (8.7)
Published Date
17/09/2026
Last Modified
18/09/2026
Exploitation Status
????
EPSS Score
0.39% (percentile 33.2%)

CVSS Base Metrics

CVSS v3 (3.1)
HIGH 8.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Weaknesses (CWE)

CWE-79 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected & Patched Versions

ProductAffected VersionsPatched Version
opencast opencast< 19.7, >= 20.0, < 20.2N/A
polimediaupv paella-player< 2.12.11N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.