Vulnerabilities (CVE)

Filtered by vendor Videowhisper Subscribe
Filtered by product Video Conference
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9271 1 Videowhisper 1 Video Conference 2024-11-21 7.5 HIGH 9.8 CRITICAL
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-1905.