VYPR

Html5 Video Player

by Socusoft

CVEs (3)

  • CVE-2019-25689HigApr 12, 2026
    risk 0.55cvss 8.4epss 0.00

    HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help…

  • CVE-2024-5522MedJun 20, 2024
    risk 0.42cvss 6.5epss 0.03

    The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

  • CVE-2023-6485MedJan 1, 2024
    risk 0.35cvss 5.4epss 0.01

    The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting…