Unrated severityNVD Advisory· Published Feb 1, 2026· Updated Mar 5, 2026
PHP Melody 3.0 Persistent Cross-Site Scripting via Video Editor
CVE-2021-47913
Description
PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.
Affected products
2- Range: <=3.0
- PHPSUGAR/PHP Melodyv5Range: 3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.phpsugar.com/blog/2021/09/php-melody-3-0-vulnerability-report-fix/mitrepatch
- www.vulnerability-lab.com/get_content.phpmitreexploit
- www.vulncheck.com/advisories/php-melody-persistent-cross-site-scripting-via-video-editormitrethird-party-advisory
- www.phpsugar.com/phpmelody.htmlmitreproduct
News mentions
0No linked articles in our index yet.