PT-2026-63534 · Packagist · Drupal/Media Folders

CVE-2026-16638

·

Publicado

2026-07-22

·

Atualizado

2026-07-22

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
This module provides a better UI for managing and selecting Media entities in a folder structure.
The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-16638
DRUPAL-CONTRIB-2026-080

Produtos afetados

Drupal/Media Folders