—
DRUPAL-CONTRIB-2026-131
Details
This module enables you to add dynamic caption support to PhotoSwipe image galleries.
The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/photoswipe
Introduced in:
0Fixed in: 5.0.9Upgrade drupal/photoswipe to 5.0.9 or newer (ecosystem packagist:https://packages.drupal.org/8).