Vulnerabilities (CVE)

Filtered by vendor Longtailvideo Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-2904 1 Longtailvideo 1 Jw Player 2017-08-29 4.3 MEDIUM N/A
player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via multiple "javascript:" sequences in the debug parameter.
CVE-2014-4030 1 Longtailvideo 1 Jw Player For Flash \& Html5 Video Plugin 2014-06-26 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that remove players via a delete action to wp-admin/admin.php.