Longtailvideo develops JW Player, a widely embedded video playback platform used across web and mobile applications. The vendor's vulnerability footprint is characterized by application-layer input-handling issues, particularly cross-site scripting and cross-site request forgery flaws that are typical of browser-facing media players and their integration points. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Longtailvideo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4030MEDIUM Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for reques | Jun 25, 2014 | 6.8 | 33 | NO | YES |
CVE-2012-3351MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2 | Feb 20, 2020 | 6.1 | 32 | NO | YES |
CVE-2012-2904MEDIUM player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via multiple "javascript:" sequenc | May 21, 2012 | 4.3 | 26 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Longtailvideo.
Media articles that mention a CVE ID that affects a product developed by Longtailvideo — matched by CVE ID, not by vendor name.