Extension WordPress
Vulnérabilités Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP
Cette page rassemble les failles publiées pour Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP
14 fiches
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP < 7.1.3 – Unauthenticated PHP Object Injection
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to PHP Object Injection in versions up to 7.1.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers…
[*, 7.1.3)
7.1.3
28/05/2026
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP < 7.1.3 – Authenticated (Admin+) Remote Code Execution
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.1.3 (exclusive). This makes it possible for authenticated attackers, with Administrator-level access…
[*, 7.1.3)
7.1.3
25/05/2026
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.2.4 – Cross-Site Request Forgery
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.4. This is due to missing or incorrect nonce validation…
*-6.2.4
6.2.5
19/05/2025
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.1.10 – Unauthenticated Arbitrary File Deletion
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 6.1.10.…
*-6.1.10
6.2.1
14/02/2025
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP <= 6.1.10 – Unauthenticated Arbitrary File Read
The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.10. This makes it possible for unauthenticated attackers to read the…
*-6.1.10
6.2.1
14/02/2025
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 6.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient…
*-6.1.9
6.1.10
22/01/2025
Live Streaming – Broadcast Live Video <= 5.5.15 – Missing Authorization to Unauthenticated Remote Code Execution
The Live Streaming – Broadcast Live Video Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 5.5.15. This allows unauthenticated attackers to execute code on the server.
*-5.5.15
5.5.16
20/02/2023
Broadcast Live Video – Live Streaming < 4.27.4 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.
[*, 4.27.4)
4.27.4
01/07/2014
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.27.4 – Arbitrary File Upload
Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file…
*-4.27.4
4.29.5
27/02/2014
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP < 4.29.5 – Arbitrary File Read/Deletion
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary…
[*, 4.29.5)
4.29.5
27/02/2014
Broadcast Live Video – Live Streaming < 4.29.5 – Full Path Disclosure
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path…
[*, 4.29.5)
4.29.5
27/02/2014
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.29.6 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php.…
*-4.29.6
4.29.9
26/02/2014
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP < 4.29.5 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php;…
[*, 4.29.5)
4.29.5
06/02/2014
Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP <= 4.25.3 – Reflected Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter.
*-4.25.3
4.27
23/08/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.