Cross-Site Scripting Vulnerability in Drupal Media Folders
CVE-2026-16638

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
25 August 2026

What is CVE-2026-16638?

The vulnerability in Drupal Media Folders involves improper handling of user input during web page generation, which can lead to Stored Cross-Site Scripting (XSS) attacks. This flaw allows attackers to inject malicious scripts that can be executed in the browsers of unsuspecting users, potentially leading to data theft or session hijacking. Affected versions include all Media Folders from 0.0.0 to 1.0.8, emphasizing the need for users to update their installations to safeguard against this security risk.

Affected Version(s)

Media Folders 0.0.0 < 1.0.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Drew Webber (mcdruid)
João Mauricio (jmauricio)
Juraj Nemec (poker10)
.