Junglewise Threat Intelligence

CVE-2026-84919: Drupal PhotoSwipe dynamic caption cross-site scripting

CVE-2026-84919 · Severity: info · Published 2026-09-02

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The PhotoSwipe module adds image gallery features to Drupal sites. A cross-site scripting vulnerability in the dynamic caption component allows attackers with HTML entry permissions to inject malicious scripts that execute in users' browsers, potentially stealing session data or redirecting users to malicious sites.

Technical details

The photoswipe_dynamic_caption component fails to properly sanitize user-supplied input such as image alt tags in its JavaScript caption script, enabling stored XSS. Attack requires the attacker to hold a Drupal role with HTML content entry permissions. An authenticated attacker can inject JavaScript that executes when other users view the gallery.

Affected products

  • Drupal PhotoSwipe before 5.0.9

Timeline

  • 2026-09-02: disclosed

References

Related threats