Extension WordPress
Vulnérabilités FV Flowplayer Video Player
Cette page rassemble les failles publiées pour FV Flowplayer Video Player, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de FV Flowplayer Video Player
27 fiches
FV Flowplayer Video Player <= 7.5.51.7212 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user…
*-7.5.51.7212
7.5.52.7212
30/06/2026
FV Flowplayer Video Player <= 7.5.49.7212 – Unauthenticated Stored Cross-Site Scripting via Comment Text
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible…
*-7.5.49.7212
7.5.50.7212
08/06/2026
FV Flowplayer Video Player < 7.5.51.7212 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.5.51.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and…
[*, 7.5.51.7212)
7.5.51.7212
04/06/2026
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-7.5.47.7212
7.5.48.7212
03/12/2024
FV Player <= 7.5.46.7212 – Authenticated (Subscriber+) SQL Injection via exclude Parameter
The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of…
*-7.5.46.7212
7.5.47.7212
18/07/2024
FV Flowplayer Video Player <= 7.5.45.7212 – Reflected Cross-Site Scripting
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.5.45.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-7.5.45.7212
7.5.46.7212
27/05/2024
FV Flowplayer Video Player <= 7.5.43.7212 – Authenticated (Subscriber+) Server-side Request Forgery
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.5.43.7212. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests…
*-7.5.43.7212
7.5.45.7212
22/04/2024
FV Flowplayer Video Player <= 7.5.44.7212 – Authenticated (Contributor+) Arbitrary Redirect
The FV Flowplayer Video Player plugin for WordPress is vulnerable to unauthorized redirects in all versions up to, and including, 7.5.44.7212. This is due to the plugin not restricting contributor and above users from being able to add…
*-7.5.44.7212
7.5.45.7212
11/04/2024
FV Flowplayer Video Player <= 7.5.41.7212 – Reflected Cross-Site Scripting
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.5.41.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-7.5.41.7212
7.5.44.7212
26/03/2024
FV Flowplayer Video Player <= 7.5.41.7212 – Authenticated (Contributor+) Stored Cross-Site Scripting
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.41.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-7.5.41.7212
7.5.44.7212
16/03/2024
FV Flowplayer Video Player <= 7.5.37.7212 – Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the…
*-7.5.37.7212
7.5.39.7212
24/08/2023
FV Flowplayer Video Player <= 7.5.32.7212 – Reflected Cross-Site Scripting via id
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 7.5.32.7212 due to insufficient input sanitization and output escaping. This makes it possible for…
*-7.5.32.7212
7.5.35.7212
03/05/2023
FV Flowplayer Video Player <= 7.5.30.7210 – Cross-Site Request Forgery
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.30.7210. This is due to missing or incorrect nonce validation on the settings_toggle() function. This makes it possible…
*-7.5.30.7210
7.5.31.7212
02/02/2023
FV Flowplayer Video Player <= 7.5.18.727 – Stored Cross-Site Scripting
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions
*-7.5.18.727
7.5.19.728
04/04/2022
FV Flowplayer Video Player <= 7.5.15.727 – SQL Injection
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions
*-7.5.15.727
7.5.18.727
18/03/2022
FV Flowplayer Video Player 7.5.0.727 – 7.5.2.727 – Reflected Cross-Site Scripting via player_id Parameter
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 – 7.5.2.727.
7.5.0.727-7.5.2.727
7.5.3.727
05/10/2021
FV Flowplayer Video Player <= 7.4.37.727 – Authenticated Stored Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.
*-7.4.37.727
7.4.38.727
15/01/2021
FV Flowplayer Video Player <= 7.3.18.727 – SQL Injection
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
*-7.3.18.727
7.3.19.727
11/07/2019
FV Flowplayer Video Player <= 7.3.13.727 – Unauthenticated Stored Cross-Site Scripting
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
*-7.3.13.727
7.3.14.727
20/05/2019
FV Flowplayer Video Player <= 7.3.14.727 – SQL Injection
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
[*, 7.3.15.727)
7.3.15.727
20/05/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.