FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 7.5.51.7212
- Fixed in:
- 7.5.52.7212
- Disclosed:
- Jun 30, 2026
CVE-2026-12135 on NVD →
FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text
high
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 7.2
- Affected:
- up to 7.5.49.7212
- Fixed in:
- 7.5.50.7212
- Disclosed:
- Jun 8, 2026
CVE-2026-7556 on NVD →
FV Flowplayer Video Player < 7.5.51.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.5.51.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 7.5.51.7212
- Fixed in:
- 7.5.51.7212
- Disclosed:
- Jun 4, 2026
CVE-2026-49773 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.48.7212
unknown
[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 7.5.48.7212
- Fixed in:
- 7.5.48.7212
- Disclosed:
- Dec 4, 2024
CVE-2024-5020 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 7.5.47.7212
- Fixed in:
- 7.5.48.7212
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.47.7212
unknown
[en] The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...
- Affected:
- up to 7.5.47.7212
- Fixed in:
- 7.5.47.7212
- Disclosed:
- Jul 19, 2024
CVE-2024-6338 on NVD →
FV Player <= 7.5.46.7212 - Authenticated (Subscriber+) SQL Injection via exclude Parameter
high
The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...
- CVSS:
- 8.8
- Affected:
- up to 7.5.46.7212
- Fixed in:
- 7.5.47.7212
- Disclosed:
- Jul 18, 2024
CVE-2024-6338 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.46.7212
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212.
- Affected:
- up to 7.5.46.7212
- Fixed in:
- 7.5.46.7212
- Disclosed:
- Jun 3, 2024
CVE-2024-35631 on NVD →
FV Flowplayer Video Player <= 7.5.45.7212 - Reflected Cross-Site Scripting
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.5.45.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 7.5.45.7212
- Fixed in:
- 7.5.46.7212
- Disclosed:
- May 27, 2024
CVE-2024-35631 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.45.7212
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212.
- Affected:
- up to 7.5.45.7212
- Fixed in:
- 7.5.45.7212
- Disclosed:
- Apr 24, 2024
CVE-2024-32078 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.45.7212
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.43.7212.
- Affected:
- up to 7.5.45.7212
- Fixed in:
- 7.5.45.7212
- Disclosed:
- Apr 24, 2024
CVE-2024-32955 on NVD →
FV Flowplayer Video Player <= 7.5.43.7212 - Authenticated (Subscriber+) Server-side Request Forgery
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.5.43.7212. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application...
- CVSS:
- 6.4
- Affected:
- up to 7.5.43.7212
- Fixed in:
- 7.5.45.7212
- Disclosed:
- Apr 22, 2024
CVE-2024-32955 on NVD →
FV Flowplayer Video Player <= 7.5.44.7212 - Authenticated (Contributor+) Arbitrary Redirect
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to unauthorized redirects in all versions up to, and including, 7.5.44.7212. This is due to the plugin not restricting contributor and above users from being able to add redirects at the end of videos. This makes it possible for authenticated attackers,...
- CVSS:
- 5.4
- Affected:
- up to 7.5.44.7212
- Fixed in:
- 7.5.45.7212
- Disclosed:
- Apr 11, 2024
CVE-2024-32078 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.44.7212
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.
- Affected:
- up to 7.5.44.7212
- Fixed in:
- 7.5.44.7212
- Disclosed:
- Mar 27, 2024
CVE-2024-22299 on NVD →
FV Flowplayer Video Player <= 7.5.41.7212 - Reflected Cross-Site Scripting
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.5.41.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 7.5.41.7212
- Fixed in:
- 7.5.44.7212
- Disclosed:
- Mar 26, 2024
CVE-2024-22299 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.44.7212
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.
- Affected:
- up to 7.5.44.7212
- Fixed in:
- 7.5.44.7212
- Disclosed:
- Mar 19, 2024
CVE-2024-29122 on NVD →
FV Flowplayer Video Player <= 7.5.41.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.41.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 7.5.41.7212
- Fixed in:
- 7.5.44.7212
- Disclosed:
- Mar 16, 2024
CVE-2024-29122 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.39.7212
unknown
[en] The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7...
- Affected:
- up to 7.5.39.7212
- Fixed in:
- 7.5.39.7212
- Disclosed:
- Aug 25, 2023
CVE-2023-4520 on NVD →
FV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7212 d...
- CVSS:
- 5.4
- Affected:
- up to 7.5.37.7212
- Fixed in:
- 7.5.39.7212
- Disclosed:
- Aug 24, 2023
CVE-2023-4520 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.39.7212
unknown
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7212 d...
- Affected:
- up to 7.5.39.7212
- Fixed in:
- 7.5.39.7212
- Disclosed:
- Aug 24, 2023
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.35.7212
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.
- Affected:
- up to 7.5.35.7212
- Fixed in:
- 7.5.35.7212
- Disclosed:
- Aug 18, 2023
CVE-2023-30499 on NVD →
FV Flowplayer Video Player <= 7.5.32.7212 - Reflected Cross-Site Scripting via id
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 7.5.32.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 7.5.32.7212
- Fixed in:
- 7.5.35.7212
- Disclosed:
- May 3, 2023
CVE-2023-30499 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.31.7212
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.
- Affected:
- up to 7.5.31.7212
- Fixed in:
- 7.5.31.7212
- Disclosed:
- Feb 14, 2023
CVE-2023-25066 on NVD →
FV Flowplayer Video Player <= 7.5.30.7210 - Cross-Site Request Forgery
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.30.7210. This is due to missing or incorrect nonce validation on the settings_toggle() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via...
- CVSS:
- 4.3
- Affected:
- up to 7.5.30.7210
- Fixed in:
- 7.5.31.7212
- Disclosed:
- Feb 2, 2023
CVE-2023-25066 on NVD →
FV Flowplayer Video Player <= 7.5.18.727 - Stored Cross-Site Scripting
medium
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
- CVSS:
- 6.4
- Affected:
- up to 7.5.18.727
- Fixed in:
- 7.5.19.728
- Disclosed:
- Apr 4, 2022
CVE-2022-25613 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.19.728
unknown
[en] Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
- Affected:
- up to 7.5.19.728
- Fixed in:
- 7.5.19.728
- Disclosed:
- Apr 4, 2022
CVE-2022-25613 on NVD →
FV Flowplayer Video Player <= 7.5.15.727 - SQL Injection
high
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
- CVSS:
- 7.2
- Affected:
- up to 7.5.15.727
- Fixed in:
- 7.5.18.727
- Disclosed:
- Mar 18, 2022
CVE-2022-25607 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.18.727
unknown
[en] Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
- Affected:
- up to 7.5.18.727
- Fixed in:
- 7.5.18.727
- Disclosed:
- Mar 18, 2022
CVE-2022-25607 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] >= 7.5.0.727 - <= 7.5.2.727
unknown
[en] The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
- Affected:
- 7.5.0.727 – 7.5.2.727
- Fixed in:
- 7.5.2.727
- Disclosed:
- Oct 6, 2021
CVE-2021-39350 on NVD →
FV Flowplayer Video Player 7.5.0.727 - 7.5.2.727 - Reflected Cross-Site Scripting via player_id Parameter
medium
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
- CVSS:
- 6.1
- Affected:
- 7.5.0.727 – 7.5.2.727
- Fixed in:
- 7.5.3.727
- Disclosed:
- Oct 5, 2021
CVE-2021-39350 on NVD →
FV Flowplayer Video Player <= 7.4.37.727 - Authenticated Stored Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.
- CVSS:
- 6.4
- Affected:
- up to 7.4.37.727
- Fixed in:
- 7.4.38.727
- Disclosed:
- Jan 15, 2021
CVE-2020-35748 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.4.37.727
unknown
[en] Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.
- Affected:
- up to 7.4.37.727
- Fixed in:
- 7.4.37.727
- Disclosed:
- Jan 15, 2021
CVE-2020-35748 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727
unknown
[en] The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- Aug 15, 2019
CVE-2019-14800 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.14.727
unknown
[en] The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
- Affected:
- up to 7.3.14.727
- Fixed in:
- 7.3.14.727
- Disclosed:
- Aug 9, 2019
CVE-2019-14799 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727
unknown
[en] The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- Aug 9, 2019
CVE-2019-14801 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.19.727
unknown
[en] A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- Affected:
- up to 7.3.19.727
- Fixed in:
- 7.3.19.727
- Disclosed:
- Jul 17, 2019
CVE-2019-13573 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.19.727
unknown
SQL Injection (SQLi) vulnerability found by Tin Duong in WordPress FV Flowplayer Video Player plugin (versions <= 7.3.18.727).
- Affected:
- up to 7.3.19.727
- Fixed in:
- 7.3.19.727
- Disclosed:
- Jul 13, 2019
FV Flowplayer Video Player <= 7.3.18.727 - SQL Injection
critical
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- CVSS:
- 9.8
- Affected:
- up to 7.3.18.727
- Fixed in:
- 7.3.19.727
- Disclosed:
- Jul 11, 2019
CVE-2019-13573 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727
unknown
CSV Export vulnerability found in WordPress FV Flowplayer Video Player plugin (versions <= 7.3.14.727).
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- May 21, 2019
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.14.727
unknown
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found in WordPress FV Flowplayer Video Player plugin (versions <= 7.3.13.727).
- Affected:
- up to 7.3.14.727
- Fixed in:
- 7.3.14.727
- Disclosed:
- May 21, 2019
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727
unknown
SQL Injection (SQLi) vulnerability found in WordPress FV Flowplayer Video Player plugin (versions <= 7.3.14.727).
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- May 21, 2019
FV Flowplayer Video Player <= 7.3.14.727 - SQL Injection
critical
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
- CVSS:
- 9.8
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- May 20, 2019
CVE-2019-14801 on NVD →
FV Flowplayer Video Player <= 7.3.13.727 - Unauthenticated Stored Cross-Site Scripting
medium
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
- CVSS:
- 6.1
- Affected:
- up to 7.3.13.727
- Fixed in:
- 7.3.14.727
- Disclosed:
- May 20, 2019
CVE-2019-14799 on NVD →
FV Flowplayer Video Player <= 7.3.14.727 - Sensitive Information Exposure
medium
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.
- CVSS:
- 5.3
- Affected:
- up to 7.3.14.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- May 20, 2019
CVE-2019-14800 on NVD →
FV Flowplayer Video Player <= 7.3.14.727 - Unauthenticated SQL Injection
critical
The FV Flowplayer Video Player plugin for WordPress is vulnerable to SQL injection in versions up to, and including, 7.3.14.727 in the 'email_signup' function. This makes it possible for Unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive inform...
- CVSS:
- 9.3
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- May 16, 2019
FV Flowplayer Video Player <= 7.3.14.727 - Sensitive Data Exposure
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to sensitive data exposure in versions up to, and including, 7.3.14.727 via the 'csv_export' function. This makes it possible for attackers to export a CSV of email subscribers.
- CVSS:
- 5.3
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- May 16, 2019
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727
unknown
The FV Flowplayer Video Player plugin for WordPress is vulnerable to sensitive data exposure in versions up to, and including, 7.3.14.727 via the 'csv_export' function. This makes it possible for attackers to export a CSV of email subscribers.
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- May 16, 2019
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727
unknown
The FV Flowplayer Video Player plugin for WordPress is vulnerable to SQL injection in versions up to, and including, 7.3.14.727 in the 'email_signup' function. This makes it possible for Unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive inform...
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
- Disclosed:
- May 16, 2019
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.2.1.727
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found by Janek Vind "waraxe" in WordPress FV Flowplayer Video Player plugin (versions <= 7.2.0.727).
- Affected:
- up to 7.2.1.727
- Fixed in:
- 7.2.1.727
- Disclosed:
- Oct 3, 2018
FV Flowplayer Video Player <= 7.2.0.727 - Reflected Cross-Site Scripting
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fv_player_preview’ parameter in versions up to, and including, 7.2.0.727 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...
- CVSS:
- 6.1
- Affected:
- up to 7.2.0.727
- Fixed in:
- 7.2.1.727
- Disclosed:
- Sep 21, 2018
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.2.1.727
unknown
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fv_player_preview’ parameter in versions up to, and including, 7.2.0.727 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...
- Affected:
- up to 7.2.1.727
- Fixed in:
- 7.2.1.727
- Disclosed:
- Sep 21, 2018
FV Flowplayer Video Player [fv-wordpress-flowplayer] >= 6.1.2 - <= 6.6.4
unknown
[en] Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- 6.1.2 – 6.6.4
- Fixed in:
- 6.6.4
- Disclosed:
- Sep 7, 2018
CVE-2018-0642 on NVD →
FV Flowplayer Video Player 6.1.2 - 6.6.4 - Cross-Site Scripting
medium
Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- 6.1.2 – 6.6.4
- Fixed in:
- 6.6.5
- Disclosed:
- Jul 2, 2018
CVE-2018-0642 on NVD →
FV Flowplayer Video Player <= 6.0.3.3 - Stored Cross-Site Scripting
medium
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 6.0.3.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute...
- CVSS:
- 5.3
- Affected:
- up to 6.0.3.3
- Fixed in:
- 6.0.3.4
- Disclosed:
- Aug 24, 2015
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 6.0.3.4
unknown
Because of this vulnerability, authenticated administrators can store HTML or JS code in plugin configuration values.
Upgrade this plugin.
- Affected:
- up to 6.0.3.4
- Fixed in:
- 6.0.3.4
- Disclosed:
- Aug 24, 2015
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 6.0.3.4
unknown
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 6.0.3.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute...
- Affected:
- up to 6.0.3.4
- Fixed in:
- 6.0.3.4
- Disclosed:
- Aug 24, 2015
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 1.2.12
unknown
[en] Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI.
- Affected:
- up to 1.2.12
- Fixed in:
- 1.2.12
- Disclosed:
- Nov 29, 2011
CVE-2011-4568 on NVD →
FV Flowplayer Video Player <= 1.2.11 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI.
- CVSS:
- 6.1
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.12
- Disclosed:
- Jul 22, 2011
CVE-2011-4568 on NVD →
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 6.0.3.4
unknown
The FV Flowplayer Video Player WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 6.0.3.4
- Fixed in:
- 6.0.3.4
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.2.1.727
unknown
The FV Flowplayer Video Player WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 7.2.1.727
- Fixed in:
- 7.2.1.727
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.3.15.727
unknown
Changelog states:
Security - fix for email subscription CSV export capability available to guest users
- Affected:
- up to 7.3.15.727
- Fixed in:
- 7.3.15.727
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.3.727
unknown
The plugin does not escape or validate the player_id parameter before outputting back in the Stats page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
- Affected:
- up to 7.5.3.727
- Fixed in:
- 7.5.3.727