Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2014-4570 | 1 Videowhisper | 1 Video Presentation | 2025-04-12 | N/A | 
| Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/. | ||||
| CVE-2015-9272 | 1 Videowhisper | 1 Video Presentation | 2024-11-21 | N/A | 
| The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code. | ||||
                            
                                
                                
                                    Page 1 of 1.