PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-131
View online: https://www.drupal.org/sa-contrib-2026-131 Project: PhotoSwipe - Responsive JavaScript Modal Image Gallery [1] Date: 2026-September-02 Security risk: *Moderately critical* 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross-site scripting Affected versions: <5.0.9 CVE IDs: CVE-2026-84919 Description: This module enables you to add dynamic caption support to PhotoSwipe image galleries. The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability. This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content. Solution: Install the latest version: * If you use the photoswipe_dynamic_caption module, upgrade to photoswipe 5.0.9 [3] Reported By: * Pierre Rudloff (prudloff) [4] of the Drupal Security Team Fixed By: * Bram Driesen (bramdriesen) [5] of the Drupal Security Team * Joshua Sedler (grevil) [6] * Pierre Rudloff (prudloff) [7] of the Drupal Security Team Coordinated By: * Greg Knaddison (greggles) [8] of the Drupal Security Team * Pierre Rudloff (prudloff) [9] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [10] [1] https://www.drupal.org/project/photoswipe [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/photoswipe/releases/5.0.9 [4] https://www.drupal.org/u/prudloff [5] https://www.drupal.org/u/bramdriesen [6] https://www.drupal.org/u/grevil [7] https://www.drupal.org/u/prudloff [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/prudloff [10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org