Happyworm Jplayer vulnerabilities

3 known vulnerabilities affecting happyworm/jplayer.

Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2013-2022MEDIUMCVSS 4.3≤ 2.2.22v0.2.1+67 more2013-08-17
CVE-2013-2022 [MEDIUM] CVE-2013-2022: Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF comp Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in th
ghsanvdosv
CVE-2013-1942MEDIUMCVSS 4.3PoC≤ 2.2.19v0.2.1+71 more2013-08-15
CVE-2013-1942 [MEDIUM] CWE-79 CVE-2013-1942: Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF comp Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as demonstrated using document.write in the j
nvd
CVE-2013-2023MEDIUMCVSS 4.3≤ 2.3.0v0.2.1+78 more2013-08-15
CVE-2013-2023 [MEDIUM] CVE-2013-2023: Cross-site scripting (XSS) vulnerability in actionscript/Jplayer.as in the Flash SWF component (jpla Cross-site scripting (XSS) vulnerability in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to incomplete blacklists, a different vulnerability than CVE-2013-1942 and CVE-2013-2022.
nvd