Project: 
Date: 
2026-July-22
Vulnerability: 
Cross site scripting
Affected versions: 
<1.0.8
CVE IDs: 
CVE-2026-16638
Description: 

This module provides a better UI for managing and selecting Media entities in a folder structure.

The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: