Date: 
2026-September-02
Vulnerability: 
Cross-site scripting
Affected versions: 
<5.0.9
CVE IDs: 
CVE-2026-84919
Description: 

This module enables you to add dynamic caption support to PhotoSwipe image galleries.

The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.

Solution: 

Install the latest version:

Reported By: 
Fixed By: 
Coordinated By: