backdropcms Vulnerabilities and Affected Products
Vulnerabilities associated with backdrop.
Products
Clear product- backdrop3 vulnerabilities
- Bootstrap 5 Lite theme1 vulnerability
- Bootstrap Lite theme1 vulnerability
- Flag1 vulnerability
- GDPR cookies module for Backdrop CMS1 vulnerability
- Link iframe formatter1 vulnerability
- Mail Disguise1 vulnerability
- Masquerade1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-25062MEDIUM | Backdrop CMS - Cross-Site ScriptingAn XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attacker must have the ability to create long text content (such as through the node or comment forms) and … | CVSS4.4v3.1 | EPSS1.69% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-25063MEDIUM | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and executable scripting, and using a crafted SVG, it is possible to execute scripting in the browser when an SVG image is viewed. This issue is mitigated by the attacker needing to be able to upload SVG images, and that Backdrop embeds all uploaded SVG … CWE-79Feb 3, 2025 | CVSS4.4v3.1 | EPSS0.196% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Cross-site Scripting in Backdrop CMSA stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via the name parameter. When a user is editing any content type (e.g., page, post, or card) as an admin, the stored XSS payload is executed upon selecting a malicious text formatting option. NOTE: the vendor disputes the security relevance of this finding because "any administrator that can configure a text format could easily allow Fu… CWE-79Apr 24, 2023 | CVSS-v4.0 | EPSS0.536% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |