Drupal · Media Folders · CVE-2026-16638
**Name of the Vulnerable Software and Affected Versions**
Drupal Media Folders versions 0.0.0 through 1.0.8
**Description**
Stored cross-site scripting (XSS) occurs because the module does not sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser. This allows an attacker with permissions to create or edit media items or folders to inject malicious scripts. Cross-site scripting is a technique where malicious scripts are injected into trusted websites.
**Recommendations**
Update Drupal Media Folders to a version later than 1.0.8.