backdropcms Vulnerabilities and Affected Products
Vulnerabilities associated with Mail Disguise.
Products
Clear product- backdrop3 vulnerabilities
- Bootstrap 5 Lite theme1 vulnerability
- Bootstrap Lite theme1 vulnerability
- Flag1 vulnerability
- GDPR cookies module for Backdrop CMS1 vulnerability
- Link iframe formatter1 vulnerability
- Mail Disguise1 vulnerability
- Masquerade1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-27823MEDIUM | An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdrop CMS. It enables a website to obfuscate email addresses, and should prevent spambots from collecting them. The module doesn't sufficiently validate the data attribute value on links, potentially leading to a Cross Site Scripting (XSS) vulnerability. This is mitigated by the fact an attacker must be able to insert link (<a>) HTML elements containing data attributes into the page. CWE-79Mar 7, 2025 | CVSS6.4v3.1 | EPSS0.227% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |