Extension WordPress

Vulnérabilités FV Flowplayer Video Player

Cette page rassemble les failles publiées pour FV Flowplayer Video Player, leurs plages de versions affectées et les correctifs signalés dans la base locale.

27Vulnérabilités
3Critiques
27Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de FV Flowplayer Video Player

27 fiches

CVE-2026-12135 Moyenne · 6,4
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.5.51.7212 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-7.5.51.7212

Correctif

7.5.52.7212

Publication

30/06/2026

CVE-2026-7556 Élevée · 7,2
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.5.49.7212 – Unauthenticated Stored Cross-Site Scripting via Comment Text

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-7.5.49.7212

Correctif

7.5.50.7212

Publication

08/06/2026

CVE-2026-49773 Moyenne · 6,4
FV Flowplayer Video Player

FV Flowplayer Video Player < 7.5.51.7212 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.5.51.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and…

Versions affectées

[*, 7.5.51.7212)

Correctif

7.5.51.7212

Publication

04/06/2026

CVE-2024-5020 Moyenne · 6,4
FV Flowplayer Video Player

Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-7.5.47.7212

Correctif

7.5.48.7212

Publication

03/12/2024

CVE-2024-6338 Élevée · 8,8
FV Flowplayer Video Player

FV Player <= 7.5.46.7212 – Authenticated (Subscriber+) SQL Injection via exclude Parameter

The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-7.5.46.7212

Correctif

7.5.47.7212

Publication

18/07/2024

CVE-2024-35631 Moyenne · 6,1
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.5.45.7212 – Reflected Cross-Site Scripting

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.5.45.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-7.5.45.7212

Correctif

7.5.46.7212

Publication

27/05/2024

CVE-2024-32955 Moyenne · 6,4
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.5.43.7212 – Authenticated (Subscriber+) Server-side Request Forgery

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.5.43.7212. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests…

Versions affectées

*-7.5.43.7212

Correctif

7.5.45.7212

Publication

22/04/2024

CVE-2024-22299 Moyenne · 6,1
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.5.41.7212 – Reflected Cross-Site Scripting

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.5.41.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-7.5.41.7212

Correctif

7.5.44.7212

Publication

26/03/2024

CVE-2024-29122 Moyenne · 6,4
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.5.41.7212 – Authenticated (Contributor+) Stored Cross-Site Scripting

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.5.41.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-7.5.41.7212

Correctif

7.5.44.7212

Publication

16/03/2024

CVE-2023-4520 Moyenne · 5,4
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.5.37.7212 – Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the…

Versions affectées

*-7.5.37.7212

Correctif

7.5.39.7212

Publication

24/08/2023

CVE-2023-30499 Moyenne · 6,1
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.5.32.7212 – Reflected Cross-Site Scripting via id

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 7.5.32.7212 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-7.5.32.7212

Correctif

7.5.35.7212

Publication

03/05/2023

CVE-2021-39350 Moyenne · 6,1
FV Flowplayer Video Player

FV Flowplayer Video Player 7.5.0.727 – 7.5.2.727 – Reflected Cross-Site Scripting via player_id Parameter

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 – 7.5.2.727.

Versions affectées

7.5.0.727-7.5.2.727

Correctif

7.5.3.727

Publication

05/10/2021

CVE-2020-35748 Moyenne · 6,4
FV Flowplayer Video Player

FV Flowplayer Video Player <= 7.4.37.727 – Authenticated Stored Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.

Versions affectées

*-7.4.37.727

Correctif

7.4.38.727

Publication

15/01/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités