Vulnerabilities > Foliovision > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-19 CVE-2024-6338 SQL Injection vulnerability in Foliovision FV Flowplayer Video Player
The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
foliovision CWE-89
8.8
2023-02-14 CVE-2023-25066 Cross-Site Request Forgery (CSRF) vulnerability in Foliovision FV Flowplayer Video Player
Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.
network
low complexity
foliovision CWE-352
8.8
2019-08-09 CVE-2019-14801 SQL Injection vulnerability in Foliovision FV Flowplayer Video Player
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
network
low complexity
foliovision CWE-89
7.5