目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

Foliovision 厂商漏洞列表 / CVE 中文分析 19

Foliovision 厂商相关 19 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

该厂商专注于视频播放器和WordPress插件开发,为网站提供媒体解决方案。历史上,其产品多次出现远程代码执行、跨站脚本和权限绕过漏洞,尤其在视频处理和权限管理模块问题突出。截至最新统计,已记录16条CVE漏洞,其中多数涉及未经验证的输入处理和不当的访问控制机制。安全社区建议及时更新并严格配置相关组件,以防范潜在攻击。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-12135 FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode — FV Flowplayer Video PlayerCWE-79 6.4 Medium2026-07-01
CVE-2026-49773 WordPress FV Flowplayer Video Player plugin < 7.5.51.7212 - Cross Site Scripting (XSS) vulnerability — FV Flowplayer Video PlayerCWE-79 6.5 Medium2026-06-15
CVE-2026-7556 FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text — FV Flowplayer Video PlayerCWE-79 7.2 High2026-06-09
CVE-2025-68579 WordPress FV Simpler SEO plugin <= 1.9.6 - Broken Access Control vulnerability — FV Simpler SEOCWE-862 5.3 Medium2025-12-24
CVE-2025-66102 WordPress FV Antispam plugin <= 2.7 - Cross Site Scripting (XSS) vulnerability — FV AntispamCWE-79 7.1 High2025-12-18
CVE-2025-32610 WordPress Foliopress WYSIWYG plugin <= 2.6.18 - CSRF to Stored XSS vulnerability — Foliopress WYSIWYGCWE-352 7.1 High2025-04-09
CVE-2025-22628 WordPress Filled In Plugin <= 1.9.2 - CSRF to Stored XSS vulnerability — Filled InCWE-79 7.1 High2025-03-27
CVE-2025-24613 WordPress FV Thoughtful Comments plugin <= 0.3.5 - Broken Access Control vulnerability — FV Thoughtful CommentsCWE-862 4.3 Medium2025-01-24
CVE-2024-56032 WordPress FV Descriptions plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability — FV DescriptionsCWE-79 7.1 High2025-01-02
CVE-2024-6338 FV Player <= 7.5.46.7212 - Authenticated (Subscriber+) SQL Injection via exclude Parameter — FV Flowplayer Video PlayerCWE-89 8.8 High2024-07-19
CVE-2024-35631 WordPress FV Flowplayer Video Player plugin <= 7.5.45.7212 - Cross Site Scripting (XSS) vulnerability — FV Flowplayer Video PlayerCWE-79 7.1 High2024-06-03
CVE-2024-32078 WordPress FV Player plugin <= 7.5.44.7212 - Unvalidated Redirects and Forwards vulnerability — FV Flowplayer Video PlayerCWE-601 4.1 Medium2024-04-24
CVE-2024-32955 WordPress FV Flowplayer Video Player plugin <= 7.5.43.7212 - Server Side Request Forgery (SSRF) vulnerability — FV Flowplayer Video PlayerCWE-918 4.9 Medium2024-04-24
CVE-2023-4520 FV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update — FV Flowplayer Video PlayerCWE-79 5.4 Medium2023-08-25
CVE-2023-30499 WordPress FV Flowplayer Video Player Plugin <= 7.5.32.7212 is vulnerable to Cross Site Scripting (XSS) — FV Flowplayer Video PlayerCWE-79 7.1 High2023-08-18
CVE-2023-25066 WordPress FV Flowplayer Video Player Plugin <= 7.5.30.7212 is vulnerable to Cross Site Request Forgery (CSRF) — FV Flowplayer Video PlayerCWE-352 4.3 Medium2023-02-14
CVE-2022-25613 WordPress FV Flowplayer Video Player plugin <= 7.5.18.727 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability — FV Flowplayer Video Player (WordPress plugin)CWE-79 4.1 Medium2022-04-04
CVE-2022-25607 WordPress FV Flowplayer Video Player plugin <= 7.5.15.727 - SQL Injection (SQLi) vulnerability — FV Flowplayer Video Player (WordPress plugin)CWE-89 6.6 Medium2022-03-18
CVE-2018-0642 FV Flowplayer Video Player 跨站脚本漏洞 — FV Flowplayer Video Player 6.1 -2018-09-07

本页汇总了 Foliovision 厂商截至目前公开的全部 19 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。