Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FV Flowplayer Video Player — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in FV Flowplayer Video Player, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the FV Flowplayer Video Player, a widely used web-based media playback solution. It catalogs a variety of weakness classes affecting the software, including cross-site scripting, path traversal, and improper input validation issues that have been publicly disclosed or analyzed by security researchers. The content covers vulnerability data spanning from the early adoption of the plugin to recent updates, ensuring a comprehensive historical perspective on its security posture. By reviewing this aggregated data, users and security professionals can track vendor advisories and patch releases to maintain a secure environment. Readers can also use this resource to understand specific weakness classes relevant to media player implementations and examine the product's historical vulnerability trends. This helps in assessing risk levels and prioritizing remediation efforts. The information presented here is organized for easy navigation, allowing for quick lookups of specific issues without the noise of unrelated data. It serves as a central reference point for understanding how past flaws have been addressed and what ongoing concerns might exist. By providing a clear view of the threat landscape, this page supports informed decision-making for administrators and developers relying on the FV Flowplayer Video Player.

Vendor: Foliovision

CVE IDTitleCVSSSeverityPublished
CVE-2026-12135 FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode CWE-79 6.4 Medium2026-07-01
CVE-2026-49773 WordPress FV Flowplayer Video Player plugin < 7.5.51.7212 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-06-15
CVE-2026-7556 FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text CWE-79 7.2 High2026-06-09
CVE-2024-6338 FV Player <= 7.5.46.7212 - Authenticated (Subscriber+) SQL Injection via exclude Parameter CWE-89 8.8 High2024-07-19
CVE-2024-35631 WordPress FV Flowplayer Video Player plugin <= 7.5.45.7212 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-06-03
CVE-2024-32078 WordPress FV Player plugin <= 7.5.44.7212 - Unvalidated Redirects and Forwards vulnerability CWE-601 4.1 Medium2024-04-24
CVE-2024-32955 WordPress FV Flowplayer Video Player plugin <= 7.5.43.7212 - Server Side Request Forgery (SSRF) vulnerability CWE-918 4.9 Medium2024-04-24
CVE-2024-22299 WordPress FV Player plugin <= 7.5.41.7212 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-03-27
CVE-2024-29122 WordPress FV Player plugin <= 7.5.41.7212 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-03-19
CVE-2023-4520 FV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta Update CWE-79 5.4 Medium2023-08-25
CVE-2023-30499 WordPress FV Flowplayer Video Player Plugin <= 7.5.32.7212 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High2023-08-18
CVE-2023-25066 WordPress FV Flowplayer Video Player Plugin <= 7.5.30.7212 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-02-14
CVE-2021-39350 FV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting CWE-79 6.1 -2021-10-06
CVE-2018-0642 FV Flowplayer Video Player 跨站脚本漏洞 6.1 -2018-09-07

All 14 known CVE vulnerabilities affecting FV Flowplayer Video Player with full Chinese analysis, references, and POCs where available.