PT-2026-84895 · Packagist · Drupal/Photoswipe

CVE-2026-84919

·

Published

2026-09-02

·

Updated

2026-09-02

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables you to add dynamic caption support to PhotoSwipe image galleries.
The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-84919
DRUPAL-CONTRIB-2026-131

Affected Products

Drupal/Photoswipe