Executive brief
The PhotoSwipe module adds image gallery features to Drupal sites. A cross-site scripting vulnerability in the dynamic caption component allows attackers with HTML entry permissions to inject malicious scripts that execute in users' browsers, potentially stealing session data or redirecting users to malicious sites.
Technical details
The photoswipe_dynamic_caption component fails to properly sanitize user-supplied input such as image alt tags in its JavaScript caption script, enabling stored XSS. Attack requires the attacker to hold a Drupal role with HTML content entry permissions. An authenticated attacker can inject JavaScript that executes when other users view the gallery.
Affected products
- Drupal PhotoSwipe before 5.0.9
Timeline
- 2026-09-02: disclosed