PatchSiren

Kaltura CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Kaltura CVE published 2026-08-25

CVE-2026-19913

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non-HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the client in an [truncated]

CRITICAL Kaltura CVE published 2026-08-25

CVE-2026-19912

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. This vulnerability allows an attacker to write arbitrary files into web-accessible locations and achieve code execution as the webserver user. Organizations using the Kaltura HTML5 player, particularly those with p [truncated]

MEDIUM Kaltura CVE published 2017-03-02

CVE-2017-6392

CVE-2017-6392 is a cross-site scripting flaw in Kaltura Server Lynx-12.11.0. The issue is caused by insufficient filtering of user-supplied data sent to the admin_console/web/tools/XmlJWPlayer.php endpoint, allowing injected HTML or script to run in a browser in the context of the vulnerable site. NVD rates the issue 6.1 MEDIUM with network exposure and required user interaction.

MEDIUM Kaltura CVE published 2017-03-02

CVE-2017-6391

CVE-2017-6391 is a cross-site scripting (XSS) vulnerability in Kaltura Server Lynx-12.11.0. The issue affects multiple admin_console web tool URLs and can let attacker-controlled HTML or script execute in a browser in the context of the vulnerable Kaltura website. Because exploitation requires user interaction and can affect authenticated admin workflows, it should be treated as a meaningful web applicati [truncated]