Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2022-25613
Disclosure Date: April 04, 2022 (last updated October 07, 2023)
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
0
Attacker Value
Unknown
CVE-2022-25607
Disclosure Date: March 18, 2022 (last updated October 07, 2023)
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
0
Attacker Value
Unknown
CVE-2021-39350
Disclosure Date: October 05, 2021 (last updated November 28, 2024)
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
0
Attacker Value
Unknown
CVE-2020-35748
Disclosure Date: January 15, 2021 (last updated November 28, 2024)
Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.
0
Attacker Value
Unknown
CVE-2019-14800
Disclosure Date: August 15, 2019 (last updated November 27, 2024)
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.
0
Attacker Value
Unknown
CVE-2019-14801
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
0
Attacker Value
Unknown
CVE-2019-14799
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
0
Attacker Value
Unknown
CVE-2019-13573
Disclosure Date: July 17, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
0
Attacker Value
Unknown
CVE-2018-0642
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0