Medium severity6.1NVD Advisory· Published Oct 1, 2021· Updated Jun 17, 2026
CVE-2021-40926
CVE-2021-40926
Description
Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
james-heinrich/getid3Packagist | >= 1.0.0, < 1.9.21 | 1.9.21 |
Affected products
4- getID3/getID3description
Patches
Vulnerability mechanics
References
5- github.com/JamesHeinrich/getID3/issues/341nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-x2gw-85w6-fjjwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-40926ghsaADVISORY
- github.com/JamesHeinrich/getID3/pull/342ghsaWEB
- github.com/JamesHeinrich/getID3/releases/tag/v1.9.21ghsaWEB
News mentions
0No linked articles in our index yet.