CVE-2022-3985

Videojs HTML5 Player < 1.1.9 - Contributor+ Stored XSS

The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks


We have discovered 627 live websites that are affected by CVE-2022-3985.

Run a Free Instant Scan




Affected Software

Product  Videojs Html5 Player
Category Wordpress Plugins
Vulnerable Domains627 live websites (18% of Videojs Html5 Player install base)
Vulnerable Versions
  • from 0 through 1.1.9
Vulnerable Versions Count12 versions ( 67% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 19, 2022
  • Updated - Apr 17, 2025

Credits

  • Lana Codes (finder)

Website Distribution by Country

Number of websites using CVE-2022-3985
United States163 websites



Germany100 websites
Italy46 websites
France41 websites
Russia33 websites
China22 websites
GB22 websites
Netherlands20 websites
Poland15 websites
Canada14 websites

Website Distribution by TLD

Number of websites using CVE-2022-3985
.com265 websites
.de57 websites
.it33 websites
.org29 websites
.ru27 websites
.nl18 websites
.fr16 websites
.co.uk11 websites
.eu10 websites
.pl10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-3985

Top websites that are affected by CVE-2022-3985. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*****.**.kr Korea, South***,***
****.*******.org Germany***,***
*********.*******.de Germany***,***
********.*******.com United States***,***
********.info Italy***,***
***************.com United States***,***
**************.**.uk GB***,***
*********.com Iran***,***
**.***.ru Russia***,***
*********.com United States***,***
See full domain list

FAQ

CVE-2022-3985 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Videojs Html5 Player
A total of 627 websites have been identified as vulnerable to CVE-2022-3985, based on global website indexing conducted by WebTechSurvey.
The Videojs Html5 Player is affected by the CVE-2022-3985 vulnerability.
Videojs Html5 Player versions up to 1.1.9 are vulnerable to CVE-2022-3985.
CVE-2022-3985 is resolved in version 1.1.9 of Videojs Html5 Player.