ZeroHour

CVE-2026-76782

niche

Cross-site scripting (XSS) in Drupal Screenshot module

CVSS 3.1
7.3 high
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-76782 is a cross-site scripting (XSS) flaw (CWE-79) in the Screenshot module for Drupal. The CVSS vector (AV:N/AC:H/PR:H/UI:R/S:C) indicates the attack occurs over a network, requires high attack complexity, requires the attacker to hold elevated (admin-level) privileges, and requires user interaction - consistent with a privileged user's injected script executing when another user, likely another privileged user, loads the affected page, with the attack crossing a security boundary (scope changed). A successful attacker could execute script in a victim's browser, potentially stealing session data or performing actions with that user's privileges. The advisory lists all versions of Screenshot (*.*) as affected and does not identify a fixed release in the available data. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.

What to do: Monitor the Screenshot module's project page on Drupal.org and the Drupal Security Team advisories for a patched release, and update as soon as a fixed version is published; if the module is not essential, disable or uninstall it until a fix ships. Because exploitation requires admin-level privileges and user interaction, review which accounts hold administrative roles and remove unnecessary privileged access as an interim mitigation.

Affected
Drupal (contributed module) Screenshotall versions (*.*); no fixed version specified in the available data
Estimated exposure
nichelikely low hundreds to low thousands of Drupal sites (niche contributed module; no install-count data provided) — No usage statistics were included in the source data, so the estimate relies on the typical deployment pattern that most niche Drupal contributed modules have small install bases, rather than on a measured active-install count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.

Ecosystems
Drupal
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.