VDB
Sign up

DRUPAL-CONTRIB-2026-131

Details

This module enables you to add dynamic caption support to PhotoSwipe image galleries.

The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/photoswipe
Introduced in: 0Fixed in: 5.0.9

Upgrade drupal/photoswipe to 5.0.9 or newer (ecosystem packagist:https://packages.drupal.org/8).

References