VDB
KO

DRUPAL-CONTRIB-2026-080

Details

This module provides a better UI for managing and selecting Media entities in a folder structure.

The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/media_folders
Introduced in: 0 Fixed in: 1.0.8

Upgrade drupal/media_folders to 1.0.8 or newer (ecosystem packagist:https://packages.drupal.org/8).

References