Foliovision's vulnerability profile centers on a focused set of web-based media and content-creation tools, including its Flowplayer video player and WordPress plugins, which occupy a prominent niche in media-publishing and digital-asset workflows. The vendor's disclosures skew toward serious outcomes with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting recurring input-handling and authentication weaknesses such as cross-site scripting, SQL injection, CSRF, and sensitive-information exposure that are characteristic of web application software. Defenders should prioritize patches for internet-exposed instances of these plugins and monitor WordPress plugin update channels closely; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Foliovision over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7556HIGH The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insuf | Jun 9, 2026 | 7.2 | 31 | NO | NO |
CVE-2019-14801CRITICAL The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. | Aug 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-13573CRITICAL A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow | Jul 17, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-39350MEDIUM The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attacker | Oct 6, 2021 | 6.1 | 30 | NO | YES |
CVE-2026-12135MEDIUM The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and inclu | Jul 1, 2026 | 6.4 | 29 | NO | NO |
CVE-2023-25066HIGH Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions. | Feb 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2026-49773MEDIUM Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions. | Jun 15, 2026 | 6.5 | 26 | NO | NO |
CVE-2024-6338HIGH The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to i | Jul 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-35631HIGH Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue | Jun 3, 2024 | 7.1 | 22 | NO | NO |
CVE-2019-14799MEDIUM The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS. | Aug 9, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Foliovision.
Media articles that mention a CVE ID that affects a product developed by Foliovision — matched by CVE ID, not by vendor name.