Foliovision
Foliovision FV Flowplayer Video Player: vulnerabilidades y CVE
Foliovision FV Flowplayer Video Player tiene 20 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-12135 | Media (6.4) | 0.35% | — | 1 jul 2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient… |
| CVE-2026-7556 | Alta (7.2) | 0.42% | — | 9 jun 2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output… |
| CVE-2024-6338 | Alta (8.8) | 0.51% | — | 19 jul 2024 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user… |
| CVE-2024-35631 | Alta (7.1) | 0.27% | — | 3 jun 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player:… |
| CVE-2024-32078 | Media (4.1) | 0.34% | — | 24 abr 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212. |
| CVE-2024-32955 | Media (4.9) | 0.25% | — | 24 abr 2024 | Server-Side Request Forgery (SSRF) vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.43.7212. |
| CVE-2024-22299 | Alta (7.1) | 0.39% | — | 27 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Reflected XSS.This issue affects FV… |
| CVE-2024-29122 | Media (6.5) | 0.34% | — | 19 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV… |
| CVE-2023-4520 | Media (6.1) | 0.56% | — | 25 ago 2023 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable… |
| CVE-2023-30499 | Media (6.1) | 0.40% | — | 18 ago 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions. |
| CVE-2023-25066 | Alta (8.8) | 0.27% | — | 14 feb 2023 | Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions. |
| CVE-2022-25613 | Media (5.4) | 0.57% | — | 4 abr 2022 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter. |
| CVE-2022-25607 | Alta (7.2) | 0.83% | — | 18 mar 2022 | Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727). |
| CVE-2021-39350 | Media (6.1) | 2.2% | — | 6 oct 2021 | The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in… |
| CVE-2020-35748 | Media (5.4) | 0.92% | — | 15 ene 2021 | Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the… |
| CVE-2019-14800 | Media (5.3) | 1.5% | — | 15 ago 2019 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI. |
| CVE-2019-14801 | Crítica (9.8) | 1.8% | — | 9 ago 2019 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. |
| CVE-2019-14799 | Media (6.1) | 2.0% | — | 9 ago 2019 | The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS. |
| CVE-2019-13573 | Crítica (9.8) | 4.4% | — | 17 jul 2019 | A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary… |
| CVE-2018-0642 | Media (6.1) | 1.0% | — | 7 sept 2018 | Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.