Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown

CVE-2023-30499

Disclosure Date: August 18, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.
Attacker Value
Unknown

CVE-2023-25066

Disclosure Date: February 14, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.
Attacker Value
Unknown

CVE-2022-3984

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-3937

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-25613

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
Attacker Value
Unknown

CVE-2022-25607

Disclosure Date: March 18, 2022 (last updated February 23, 2025)
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
Attacker Value
Unknown

CVE-2022-24927

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.
Attacker Value
Unknown

CVE-2021-24414

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
Attacker Value
Unknown

CVE-2021-39350

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
Attacker Value
Unknown

CVE-2020-35748

Disclosure Date: January 15, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.