Extension WordPress
Vulnérabilités SpiderVPlayer
Cette page rassemble les failles publiées pour SpiderVPlayer, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de SpiderVPlayer
7 fiches
Video Player <= 1.5.22 – Authenticated (Administrator+) Stored Cross-Site Scripting
The SpiderVPlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.5.22
Non indiqué
23/11/2023
Video Player <= 1.5.22 – Reflected Cross-Site Scripting
The Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.5.22
Non indiqué
11/10/2023
SpiderVPlayer < 1.5.18 – Multiple Blind Authenticated SQL Injections
The SpiderVPlayer plugin for WordPress is vulnerable to Multiple Blind Authenticated SQL Injections via the 'order_by' parameter used in various functions in versions before 1.5.18 due to a lack of sufficient preparation on the existing SQL query. This…
[*, 1.5.18)
1.5.18
19/07/2016
SpiderVPlayer< 1.5.5 – Reflected Cross-Site Scripting
The SpiderVPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions before 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
[*, 1.5.5)
1.5.5
02/02/2015
SpiderVPlayer <= 1.5.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
*-1.5.1
1.5.2
11/11/2014
SpiderVPlayer <= 2.1 – Reflected Cross-Site Scripting
The SpiderVPlayer for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_v_player_id’ parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.1
Non indiqué
09/12/2013
SpiderVPlayer <= 2.1 – SQL Injection
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.
*-2.1
Non indiqué
11/04/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.