Mediaelementjs maintains a lightweight HTML5 media player library that, despite its narrow product focus, sees widespread adoption across web applications as a standard abstraction for audio and video playback. The durable signal centers on cross-site scripting vulnerabilities arising from improper input handling in the player's web-based interface, a characteristic risk for JavaScript libraries that process user-supplied media metadata and markup. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mediaelementjs over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4567MEDIUM Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitr | May 22, 2016 | 6.1 | 24 | NO | NO |
CVE-2022-4699MEDIUM The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users wi | Jan 30, 2023 | 5.4 | 20 | NO | NO |
CVE-2013-1967MEDIUM Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows re | Feb 5, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mediaelementjs.
Media articles that mention a CVE ID that affects a product developed by Mediaelementjs — matched by CVE ID, not by vendor name.