HIGH
MediaCMS
CVE published 2026-07-21
CVE-2026-65054
CVE-2026-65054 is an information disclosure vulnerability in MediaCMS 8.2.0. Authenticated users can expose private media metadata by adding arbitrary media tokens to their playlist, bypassing access control checks. This allows retrieval of private media fields such as title, description, view count, like count, file size, author username, and encoding status.