Executive brief
The Screenshot module is a Drupal add-on that allows site administrators to capture and annotate screenshots within the site interface. The maintainer has abandoned the project and failed to address a known critical security vulnerability, leaving all versions at risk and potentially exposing site data and functionality to compromise.
Technical details
The Screenshot module for Drupal contains a critical security flaw that has not been disclosed in detail but has been marked as unfixed by the maintainer. The project is classified as unsupported and unmaintained, meaning no security patches are available or planned. All versions (denoted as "*.*") are affected. Site administrators who continue to use this module face unmitigated exposure to the vulnerability; the Drupal Security Team recommends immediate uninstallation as the primary remediation, since no patch is forthcoming.
Affected products
- Drupal Screenshot all versions
Timeline
- 2026-08-19: disclosed
- 2026-09-02: advisory