Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Videowhisper Subscribe
Filtered by product Video Presentation
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9272 1 Videowhisper 1 Video Presentation 2018-11-23 7.5 HIGH 9.8 CRITICAL
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.
CVE-2014-4570 1 Videowhisper 1 Video Presentation 2015-08-28 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/.