CVE-2014-8338: Videowhisper Webcam
Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhisper Webcam plugins for Drupal 7.x allows remote attackers to inject arbitrary web script or HTML via a URL to a crafted SVG file in the feed parameter.
Affected products
- Videowhisper Webcam: version 7.x-1.7 only
Published 2020-01-31. Last modified 2026-06-17.