PatchSiren

MediaCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH MediaCMS CVE published 2026-07-21

CVE-2026-65054

CVE-2026-65054 is an information disclosure vulnerability in MediaCMS 8.2.0. Authenticated users can expose private media metadata by adding arbitrary media tokens to their playlist, bypassing access control checks. This allows retrieval of private media fields such as title, description, view count, like count, file size, author username, and encoding status.