Kaltura's vulnerability footprint concentrates on a focused portfolio centered on its media server and player components, which are embedded in content-delivery and video-management platforms across educational and enterprise deployments. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, with the durable signal rooted in web-facing and deserialization attack surfaces: cross-site scripting in player and server interfaces, untrusted deserialization in processing pipelines, and hard-coded credential exposure in embedded systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaltura over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14143CRITICAL The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection | Sep 19, 2017 | 9.8 | 86 | NO | YES |
CVE-2017-14141HIGH The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary P | Sep 19, 2017 | 7.2 | 24 | NO | NO |
CVE-2022-4876MEDIUM A vulnerability was found in Kaltura mwEmbed up to 2.96.rc1 and classified as problematic. This issue affects some unknown processing of the file includes/DefaultSettings.php. The | Jan 4, 2023 | 6.1 | 22 | NO | NO |
CVE-2017-14142MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersio | Sep 19, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-6391MEDIUM An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "admin_console/web/tools/SimpleJ | Mar 2, 2017 | 6.1 | 21 | NO | NO |
CVE-2022-4882MEDIUM A vulnerability was found in kaltura mwEmbed up to 2.91. It has been rated as problematic. Affected by this issue is some unknown functionality of the file modules/KalturaSupport/c | Jan 9, 2023 | 4.7 | 19 | NO | NO |
CVE-2017-6392MEDIUM An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "server-Lynx-12.11.0/admin_conso | Mar 2, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaltura.
Media articles that mention a CVE ID that affects a product developed by Kaltura — matched by CVE ID, not by vendor name.