CVE-2026-76782
nicheCross-site scripting (XSS) in Drupal Screenshot module
CVE-2026-76782 is a cross-site scripting (XSS) flaw (CWE-79) in the Screenshot module for Drupal. The CVSS vector (AV:N/AC:H/PR:H/UI:R/S:C) indicates the attack occurs over a network, requires high attack complexity, requires the attacker to hold elevated (admin-level) privileges, and requires user interaction - consistent with a privileged user's injected script executing when another user, likely another privileged user, loads the affected page, with the attack crossing a security boundary (scope changed). A successful attacker could execute script in a victim's browser, potentially stealing session data or performing actions with that user's privileges. The advisory lists all versions of Screenshot (*.*) as affected and does not identify a fixed release in the available data. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Monitor the Screenshot module's project page on Drupal.org and the Drupal Security Team advisories for a patched release, and update as soon as a fixed version is published; if the module is not essential, disable or uninstall it until a fix ships. Because exploitation requires admin-level privileges and user interaction, review which accounts hold administrative roles and remove unnecessary privileged access as an interim mitigation.
| Drupal (contributed module) Screenshot | all versions (*.*); no fixed version specified in the available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
- Ecosystems
- Drupal
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.