Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Foliovision — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting Foliovision. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Foliovision develops WordPress plugins and themes, primarily for video and media management. Historically, their products have frequently contained cross-site scripting (XSS) vulnerabilities, remote code execution (RCE) flaws, and privilege escalation issues, often stemming from insufficient input validation and improper access controls. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities across their portfolio suggests a need for improved security practices. The 16 CVEs on record indicate recurring issues that could allow attackers to compromise websites, manipulate content, or gain unauthorized access, particularly in environments where their plugins are deployed with default configurations or outdated versions.

Found 13 results / 23 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-97630 FV Flowplayer Video Player <= 7.5.54.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute — FV Flowplayer Video Player CWE-79 6.4 Medium 2026-10-10
CVE-2026-42695 WordPress FV Flowplayer Video Player plugin <= 7.5.54.7212 - Cross Site Scripting (XSS) vulnerability — FV Flowplayer Video Player CWE-79 6.5 Medium 2026-10-09
CVE-2026-12135 FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode — FV Flowplayer Video Player CWE-79 6.4 Medium 2026-07-01
CVE-2026-49773 WordPress FV Flowplayer Video Player plugin < 7.5.51.7212 - Cross Site Scripting (XSS) vulnerability — FV Flowplayer Video Player CWE-79 6.5 Medium 2026-06-15
CVE-2026-7556 FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text — FV Flowplayer Video Player CWE-79 7.2 High 2026-06-09
CVE-2024-6338 FV Player <= 7.5.46.7212 - Authenticated (Subscriber+) SQL Injection via exclude Parameter — FV Flowplayer Video Player CWE-89 8.8 High 2024-07-19
CVE-2024-35631 WordPress FV Flowplayer Video Player plugin <= 7.5.45.7212 - Cross Site Scripting (XSS) vulnerability — FV Flowplayer Video Player CWE-79 7.1 High 2024-06-03
CVE-2024-32078 WordPress FV Player plugin <= 7.5.44.7212 - Unvalidated Redirects and Forwards vulnerability — FV Flowplayer Video Player CWE-601 4.1 Medium 2024-04-24
CVE-2024-32955 WordPress FV Flowplayer Video Player plugin <= 7.5.43.7212 - Server Side Request Forgery (SSRF) vulnerability — FV Flowplayer Video Player CWE-918 4.9 Medium 2024-04-24
CVE-2023-4520 FV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update — FV Flowplayer Video Player CWE-79 5.4 Medium 2023-08-25
CVE-2023-30499 WordPress FV Flowplayer Video Player Plugin <= 7.5.32.7212 is vulnerable to Cross Site Scripting (XSS) — FV Flowplayer Video Player CWE-79 7.1 High 2023-08-18
CVE-2023-25066 WordPress FV Flowplayer Video Player Plugin <= 7.5.30.7212 is vulnerable to Cross Site Request Forgery (CSRF) — FV Flowplayer Video Player CWE-352 4.3 Medium 2023-02-14
CVE-2018-0642 FV Flowplayer Video Player 跨站脚本漏洞 — FV Flowplayer Video Player 6.1 - 2018-09-07

This page lists every published CVE security advisory associated with Foliovision. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.