Executive brief
The Drupal Screenshot module is a developer tool used to capture and annotate website screenshots. The module has been marked as unsupported by the Drupal security team due to unresolved security vulnerabilities that the maintainer has not addressed. Sites using this abandoned module face unknown security risks and should uninstall it immediately.
Technical details
The Screenshot Drupal module contains documented security vulnerabilities (CVE-2026-76782 and CVE-2026-76759) that remain unpatched and unresolved. The module is no longer maintained by its original developer, and the Drupal security team has formally marked it as unsupported due to these outstanding issues. Without active maintenance or security fixes available, organizations using this module cannot remediate the vulnerabilities through normal patching channels. The vulnerability class and specific attack vectors are not publicly disclosed in detail, but the Drupal security advisory rates the overall risk as critical.
Affected products
- Drupal Screenshot all versions
Timeline
- 2026-08-19: disclosed: Marked as unsupported by Drupal security team
- 2026-09-02: advisory: CVE-2026-76782 published