Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fv Flowplayer Video Player HIGH 8.8
CVE-2024-6338

The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and …

Fix: 7.5.47.7212+
Fix from $1,950 2024-07-19
Fv Flowplayer Video Player MEDIUM 6.1
CVE-2023-4520

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via …

Fix: after 7.5.37.7212
Fix from $1,600 2023-08-25
Fv Flowplayer Video Player MEDIUM 6.1
CVE-2023-30499

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.

Fix: after 7.5.32.7212
Fix from $1,600 2023-08-18
Fv Flowplayer Video Player HIGH 8.8
CVE-2023-25066

Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.

Fix: after 7.5.30.7212
Fix from $1,950 2023-02-14
Fv Flowplayer Video Player MEDIUM 5.4
CVE-2022-25613

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_…

Fix: after 7.5.18.727
Fix from $1,600 2022-04-04
Fv Flowplayer Video Player HIGH 7.2
CVE-2022-25607

Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= …

Fix: after 7.5.15.727
Fix from $1,950 2022-03-18
Fv Flowplayer Video Player MEDIUM 6.1
CVE-2021-39350

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats…

Fix: after 7.5.2.727
Fix from $1,600 2021-10-06
Fv Flowplayer Video Player MEDIUM 5.4
CVE-2020-35748

Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows rem…

Fix: 7.4.37.727+
Fix from $1,600 2021-01-15
Fv Flowplayer Video Player MEDIUM 5.3
CVE-2019-14800

The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-ad…

Fix: 7.3.15.727+
Fix from $1,600 2019-08-15
Fv Flowplayer Video Player CRITICAL 9.8
CVE-2019-14801

The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.

Fix: 7.3.15.727+
Fix from $2,300 2019-08-09
Fv Flowplayer Video Player MEDIUM 6.1
CVE-2019-14799

The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

Fix: 7.3.14.727+
Fix from $1,600 2019-08-09
Fv Flowplayer Video Player CRITICAL 9.8
CVE-2019-13573

A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of…

Fix: 7.3.19.727+
Fix from $2,300 2019-07-17
Fv Flowplayer Video Player MEDIUM 6.1
CVE-2018-0642

Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via un…

Fix: after 6.6.4
Fix from $1,600 2018-09-07