CVE-2026-76759
nicheCross-site scripting (XSS) in Drupal Screenshot module
The Drupal contributed module "Screenshot" contains a cross-site scripting vulnerability (CWE-79) that affects all published versions of the module. Per the CVSS vector, exploitation requires an attacker who already holds high privileges on the site, favorable conditions (high attack complexity), and user interaction, with the injected script then executing in another user's browser (changed scope). A successful attack gives the attacker high confidentiality and integrity impact within that other scope, potentially compromising the victim's session or account. Any Drupal site with the Screenshot module enabled is exposed, and no patched release is specified in the available data. No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Check whether the Screenshot module is enabled on your Drupal site; if it is unused, disable and uninstall it. Monitor the module's drupal.org project page and Drupal security advisories for a patched release and update promptly when one is published. Because exploitation requires high-privileged accounts and user interaction, limit trusted/admin roles and review recently created or edited privileged content for injected markup.
| Drupal Screenshot (contributed module) | *.* (all versions; no fixed version stated in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
- Ecosystems
- Drupal
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.