—
DRUPAL-CONTRIB-2026-080
Details
This module provides a better UI for managing and selecting Media entities in a folder structure.
The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8 / drupal/media_folders
Introduced in:
0 Fixed in: 1.0.8 Upgrade drupal/media_folders to 1.0.8 or newer (ecosystem packagist:https://packages.drupal.org/8).