Getgreenshot maintains Greenshot, a lightweight screenshot and image-editing utility that, despite a narrow product footprint, reaches a broad user base across Windows environments. Its vulnerability history clusters around deserialization of untrusted data, OS command injection, and path-handling issues—attack vectors typical of utilities that process user-supplied files and invoke system commands. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getgreenshot over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34634HIGH Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened. | Aug 1, 2023 | 7.8 | 46 | NO | YES |
CVE-2025-59050HIGH Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled data received in a WM_COPYDATA message using BinaryFormatter. | Sep 16, 2025 | 7.8 | 27 | NO | NO |
CVE-2026-22035HIGH Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename processing. The FormatArguments | Jan 8, 2026 | 7.3 | 25 | NO | NO |
CVE-2026-25792MEDIUM Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path / binary hijacking vulnerability that allows a local attack | Mar 20, 2026 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getgreenshot.
Media articles that mention a CVE ID that affects a product developed by Getgreenshot — matched by CVE ID, not by vendor name.