james-heinrich has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.7 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-94106High· 8.8getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings49CVE-2026-94108Medium· 6.5getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.036
james-heinrich vulnerabilities
CVEs affecting james-heinrich, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-94106High· 8.8getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary comma…
▾ Twilightjames-heinrich · getid3EPSS 2.7%via NVD
CVE-2026-94108Medium· 6.5getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0
getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to …
▾ Sunlitjames-heinrich · getid3EPSS 0.54%via NVD