CVE-2026-77615
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7
CVSS
8.7
High
EPSS
0.4%
p33
KEV
—
Exploit Today
10
0-100
Published: Sep 17, 2026 · Last modified: Sep 22, 2026 · CWE-79
0.4%EPSS · 30 days0.4%
2026-09-182026-09-22
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
- github.comhttps://github.com/opencast/opencast/commit/701682c635f668228c3e8fb7b4564b3294788e40
- github.comhttps://github.com/opencast/opencast/pull/7736
- github.comhttps://github.com/opencast/opencast/releases/tag/19.7
- github.comhttps://github.com/opencast/opencast/releases/tag/20.2
- github.comhttps://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25
- github.comhttps://github.com/polimediaupv/paella-core/commit/94a36490808ac5a1f60a0745d71ec9253f6d206b
- github.comhttps://github.com/polimediaupv/paella-core/commit/9b2f14ec4cf55efaf4c045c77a5ed8f5ec559ab4
- github.comhttps://github.com/polimediaupv/paella-player/blob/a1b6c42467938a00a4b4d0b8c68435cd4f9d2a16/repos/paella-core/CHANGELOG.md?plain=1#L21
- github.comhttps://github.com/polimediaupv/paella-player/commit/6fe4af7306044198c8e91e2e7f4128428b83cf03
- github.comhttps://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-772725.4 MED—
——0MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an HTML page without escaping. A crafted authorization callback can inject markup or script that executes in the browser of a user completing the OAuth flow. This issue is fixed in version 0.22.0.1hCVE-2026-757448.1 HIG—
——0Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.1hCVE-2026-756989.3 CRI—
——0Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.1hCVE-2026-756979.3 CRI—
——0Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.1hCVE-2026-756899.3 CRI—
——0Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.1hCVE-2026-756849.3 CRI—
——0Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.1h