Hdwplayer develops a focused line of web-based video player and gallery products characterized by input-handling vulnerabilities, particularly cross-site scripting and SQL injection flaws in page-generation and database-query contexts. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hdwplayer over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5180MEDIUM SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to ex | Aug 6, 2014 | 6.5 | 32 | NO | YES |
CVE-2023-49178MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr. Hdwplayer HDW Player Plugin (Video Player & Video Gallery) allows Reflecte | Dec 15, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hdwplayer.
Media articles that mention a CVE ID that affects a product developed by Hdwplayer — matched by CVE ID, not by vendor name.