Skip to main content

Vendor archive

videowhisper CVEs

Beta · best-effort

25 CVEs tagged to vendor videowhisper4 Critical, 2 High, 19 Medium, 0 Low, 0 Unrated.

CVE-2025-5937

Published Jun 28, 2025

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13584

Published Jan 22, 2025

The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34759

Published Jun 4, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhisper Picture Gallery allows Stored XSS.This issue affects Pict…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52213

Published Jan 8, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings a…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-27629

Published Apr 20, 2022

Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.6 allows a remote unauthentica…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24512

Published Aug 16, 2021

The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for ha…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8338

Published Jan 31, 2020

Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhisper Webcam plugins for Drupal 7.x allows remote attackers t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4567

Published Dec 27, 2019

Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9272

Published Oct 5, 2018

The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-9271

Published Oct 4, 2018

The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4570

Published Jul 2, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4568

Published Jul 2, 2014

Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2715

Published Apr 28, 2014

Multiple cross-site scripting (XSS) vulnerabilities in vwrooms\templates\logout.tpl.php in the VideoWhisper Webcam plugins for Drupal 7.x allow remote attackers to inject arbitrar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1