VYPR

Fv Flowplayer Video Player

by WordPress

CVEs (22)

  • CVE-2022-25613MedApr 4, 2022
    risk 0.20cvss 4.1epss 0.01

    Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.

  • CVE-2026-12135MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied…

Page 2 of 2