Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080
View online: https://www.drupal.org/sa-contrib-2026-080 Project: Media Folders [1] Date: 2026-July-22 Security risk: *Moderately critical* 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross site scripting Affected versions: <1.0.8 CVE IDs: CVE-2026-16638 Description: This module provides a better UI for managing and selecting Media entities in a folder structure. The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability. This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders. Solution: Install the latest version: * If you use the Media Folders module, upgrade to Media Folder 1.0.8 [3] Reported By: * Drew Webber (mcdruid) [4] of the Drupal Security Team Fixed By: * João Mauricio (jmauricio) [5] Coordinated By: * Juraj Nemec (poker10) [6] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [7] [1] https://www.drupal.org/project/media_folders [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/media_folders/releases/1.0.8 [4] https://www.drupal.org/u/mcdruid [5] https://www.drupal.org/u/jmauricio [6] https://www.drupal.org/u/poker10 [7] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org