Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown
CVE-2023-30499
Disclosure Date: August 18, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.
0
Attacker Value
Unknown
CVE-2023-25066
Disclosure Date: February 14, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.
0
Attacker Value
Unknown
CVE-2022-3984
Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2022-3937
Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2022-25613
Disclosure Date: April 04, 2022 (last updated October 07, 2023)
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
0
Attacker Value
Unknown
CVE-2022-25607
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
0
Attacker Value
Unknown
CVE-2022-24927
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.
0
Attacker Value
Unknown
CVE-2021-24414
Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
0
Attacker Value
Unknown
CVE-2021-39350
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
0
Attacker Value
Unknown
CVE-2020-35748
Disclosure Date: January 15, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.
0