๐Ÿ” CVE Alert

CVE-2026-16638

UNKNOWN 0.0

Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.

CWE CWE-79
Vendor drupal
Product media folders
Ecosystems
Industries
WebMedia
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for drupal media folders

Be the first to know when new unknown vulnerabilities affecting drupal media folders are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Drupal / Media Folders
0.0.0 < 1.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
drupal.org: https://www.drupal.org/sa-contrib-2026-080

Credits

Drew Webber (mcdruid) Joรƒยฃo Mauricio (jmauricio) Juraj Nemec (poker10)