cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forfv-wordpress-flowplayer fv-wordpress-flowplayer

Direction: ascending
Jun 07, 2024

FV Flowplayer Video Player # CVE-2018-0642

CVE, Research URL

CVE-2018-0642

Date
Sep 07, 2018
Research Description
Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected versions
Min 6.1.2, max 6.6.4.
Status
vulnerable

FV Flowplayer Video Player # CVE-2019-14800

CVE, Research URL

CVE-2019-14800

Date
Aug 15, 2019
Research Description
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.
Affected versions
max 7.3.15.727.
Status
vulnerable

FV Flowplayer Video Player # CVE-2020-35748

CVE, Research URL

CVE-2020-35748

Date
Jan 15, 2021
Research Description
Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.
Affected versions
max 7.4.37.727.
Status
vulnerable

FV Flowplayer Video Player # CVE-2021-39350

CVE, Research URL

CVE-2021-39350

Date
Oct 06, 2021
Research Description
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
Affected versions
Min 7.5.0.727, max 7.5.2.727.
Status
vulnerable

FV Flowplayer Video Player # CVE-2019-14799

CVE, Research URL

CVE-2019-14799

Date
Aug 09, 2019
Research Description
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
Affected versions
max 7.3.14.727.
Status
vulnerable

FV Flowplayer Video Player # CVE-2019-13573

CVE, Research URL

CVE-2019-13573

Date
Jul 17, 2019
Research Description
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
Affected versions
max 7.3.19.727.
Status
vulnerable

FV Flowplayer Video Player # CVE-2011-4568

CVE, Research URL

CVE-2011-4568

Date
Nov 29, 2011
Research Description
Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI.
Affected versions
max 1.2.12.
Status
vulnerable

FV Flowplayer Video Player # CVE-2022-25607

CVE, Research URL

CVE-2022-25607

Date
Mar 18, 2022
Research Description
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
Affected versions
max 7.5.18.727.
Status
vulnerable

FV Flowplayer Video Player # CVE-2019-14801

CVE, Research URL

CVE-2019-14801

Date
Aug 09, 2019
Research Description
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
Affected versions
max 7.3.15.727.
Status
vulnerable

FV Flowplayer Video Player # CVE-2022-25613

CVE, Research URL

CVE-2022-25613

Date
Apr 05, 2022
Research Description
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
Affected versions
max 6.0.3.4.
Status
vulnerable

FV Flowplayer Video Player # CVE-2023-25066

CVE, Research URL

CVE-2023-25066

Date
Feb 14, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.
Affected versions
max 7.5.31.7212.
Status
vulnerable

FV Flowplayer Video Player # CVE-2023-30499

CVE, Research URL

CVE-2023-30499

Date
Aug 18, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.
Affected versions
max 7.5.39.7212.
Status
vulnerable

FV Flowplayer Video Player # CVE-2024-32955

CVE, Research URL

CVE-2024-32955

Date
Apr 24, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.43.7212.
Affected versions
max 7.5.45.7212.
Status
vulnerable

FV Flowplayer Video Player # CVE-2024-29122

CVE, Research URL

CVE-2024-29122

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.
Affected versions
max 7.5.44.7212.
Status
vulnerable

FV Flowplayer Video Player # CVE-2024-22299

CVE, Research URL

CVE-2024-22299

Date
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.
Affected versions
max 7.5.44.7212.
Status
vulnerable

FV Flowplayer Video Player # CVE-2024-32078

CVE, Research URL

CVE-2024-32078

Date
Apr 24, 2024
Research Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212.
Affected versions
max 7.5.45.7212.
Status
vulnerable

FV Flowplayer Video Player # CVE-2024-35631

CVE, Research URL

CVE-2024-35631

Date
Jun 03, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212.
Affected versions
max 7.5.46.7212.
Status
vulnerable

FV Flowplayer Video Player # CVE-2023-4520

CVE, Research URL

CVE-2023-4520

Date
Aug 25, 2023
Research Description
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, and makes it possible to update the user metas arbitrarily, but the meta value can only be a string.
Affected versions
max 7.5.39.7212.
Status
vulnerable
Jul 20, 2024

FV Flowplayer Video Player # CVE-2024-6338

CVE, Research URL

CVE-2024-6338

Date
Jul 19, 2024
Research Description
The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 7.5.47.7212.
Status
vulnerable
Dec 07, 2024

FV Flowplayer Video Player # CVE-2024-5020

CVE, Research URL

CVE-2024-5020

Date
Dec 04, 2024
Research Description
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 7.5.48.7212.
Status
vulnerable
Jun 10, 2026

FV Flowplayer Video Player # CVE-2026-7556

CVE, Research URL

CVE-2026-7556

Date
Jun 09, 2026
Research Description
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires an administrator to have enabled the non-default 'Parse Vimeo and YouTube links' (parse_comments) plugin setting, and requires a submitted comment to be approved by an administrator before the payload is publicly delivered.
Affected versions
max 7.5.50.7212.
Status
vulnerable

FV Flowplayer Video Player # CVE-2026-49773

CVE, Research URL

CVE-2026-49773

Date
-
Research Description
FV Flowplayer Video Player [fv-wordpress-flowplayer] < 7.5.51.7212 CVE-2026-49773
Affected versions
max 7.5.51.7212.
Status
vulnerable