CERT/CC has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library, mwEmbed (also distributed as html5lib), that allow remote, unauthenticated attackers…
CVE-2026-19912 is an unpatched vulnerability in Kaltura's mwEmbedLoader.php that allows remote, unauthenticated code execution. The flaw stems from unsafe deserialization of data…
CVE-2026-19913 is an unpatched vulnerability in Kaltura's mwEmbedLoader.php that allows remote, unauthenticated attackers to read arbitrary files from the server. The flaw…
Kaltura is a video platform provider offering tools for video management, publishing, playback, and integration. The company distributes the mwEmbed player library…
AndDone, a security research firm, is credited with discovering two unpatched vulnerabilities in Kaltura's mwEmbed player library. Researcher Gerjan Wemekamp reported the…
mwEmbed is Kaltura's HTML5 video player library, also distributed as html5lib. It contains two unpatched vulnerabilities (CVE-2026-19912 and CVE-2026-19913) in the mwEmbedLoader.php…
html5lib is the distribution name for Kaltura's mwEmbed player library. Affected releases include v2.45, v2.103 and earlier, and other v2.x releases that…
The CERT Coordination Center (CERT/CC) disclosed two unpatched vulnerabilities in Kaltura's mwEmbed player library. The flaws, CVE-2026-19912 and CVE-2026-19913, allow remote code…