Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FV Flowplayer Video Player — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in FV Flowplayer Video Player, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the FV Flowplayer Video Player, a web-based HTML5 video player. It collects disclosed security weaknesses affecting the product, covering advisories published from its initial release through the present day. Here, readers can track the vendor's security communications, analyze the specific weakness classes impacting the player, and review the historical vulnerability record for the FV Flowplayer Video Player.

Vendor: Foliovision

CVE ID Title CVSS Severity Published
CVE-2026-42695 WordPress FV Flowplayer Video Player plugin <= 7.5.54.7212 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-10-09
CVE-2026-12135 FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode CWE-79 6.4 Medium 2026-07-01
CVE-2026-49773 WordPress FV Flowplayer Video Player plugin < 7.5.51.7212 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-06-15
CVE-2026-7556 FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text CWE-79 7.2 High 2026-06-09
CVE-2024-6338 FV Player <= 7.5.46.7212 - Authenticated (Subscriber+) SQL Injection via exclude Parameter CWE-89 8.8 High 2024-07-19
CVE-2024-35631 WordPress FV Flowplayer Video Player plugin <= 7.5.45.7212 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-06-03
CVE-2024-32078 WordPress FV Player plugin <= 7.5.44.7212 - Unvalidated Redirects and Forwards vulnerability CWE-601 4.1 Medium 2024-04-24
CVE-2024-32955 WordPress FV Flowplayer Video Player plugin <= 7.5.43.7212 - Server Side Request Forgery (SSRF) vulnerability CWE-918 4.9 Medium 2024-04-24
CVE-2024-22299 WordPress FV Player plugin <= 7.5.41.7212 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-27
CVE-2024-29122 WordPress FV Player plugin <= 7.5.41.7212 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-03-19
CVE-2023-4520 FV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update CWE-79 5.4 Medium 2023-08-25
CVE-2023-30499 WordPress FV Flowplayer Video Player Plugin <= 7.5.32.7212 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-08-18
CVE-2023-25066 WordPress FV Flowplayer Video Player Plugin <= 7.5.30.7212 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium 2023-02-14
CVE-2021-39350 FV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting CWE-79 6.1 - 2021-10-06
CVE-2018-0642 FV Flowplayer Video Player 跨站脚本漏洞 6.1 - 2018-09-07

All 15 known CVE vulnerabilities affecting FV Flowplayer Video Player with full Chinese analysis, references, and POCs where available.