Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Foliovision

First CVE: Nov 29, 2011Active for: 15 yearsTotal CVEs: 22
31.4
VTI Score
Medium

Foliovision's vulnerability profile centers on a focused set of web-based media and content-creation tools, including its Flowplayer video player and WordPress plugins, which occupy a prominent niche in media-publishing and digital-asset workflows. The vendor's disclosures skew toward serious outcomes with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting recurring input-handling and authentication weaknesses such as cross-site scripting, SQL injection, CSRF, and sensitive-information exposure that are characteristic of web application software. Defenders should prioritize patches for internet-exposed instances of these plugins and monitor WordPress plugin update channels closely; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Foliovision over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 29, 2011
14 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-7556HIGH
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insuf
Jun 9, 20267.231NONO
CVE-2019-14801CRITICAL
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
Aug 9, 20199.831NONO
CVE-2019-13573CRITICAL
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow
Jul 17, 20199.831NONO
CVE-2021-39350MEDIUM
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attacker
Oct 6, 20216.130NOYES
CVE-2026-12135MEDIUM
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and inclu
Jul 1, 20266.429NONO
CVE-2023-25066HIGH
Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions.
Feb 14, 20238.827NONO
CVE-2026-49773MEDIUM
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
Jun 15, 20266.526NONO
CVE-2024-6338HIGH
The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to i
Jul 19, 20248.826NONO
CVE-2024-35631HIGH
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue
Jun 3, 20247.122NONO
CVE-2019-14799MEDIUM
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
Aug 9, 20196.122NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
64%
27%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (90.9%)
Unknown2 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (86.4%)
High1 (4.5%)
Unknown2 (9.1%)
User Interaction
None8 (36.4%)
Unknown2 (9.1%)
Required12 (54.5%)
Privileges Required
Low7 (31.8%)
High1 (4.5%)
None12 (54.5%)
Unknown2 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.5% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Foliovision.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Foliovision — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Foliovision's Products

View all 4 CNAs →

Top CWEs