CVE-2025-25062
- EPSS 24.64%
- Veröffentlicht 03.02.2025 04:15:09
- Zuletzt bearbeitet 23.01.2026 18:46:32
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and ...
CVE-2025-25063
- EPSS 0.61%
- Veröffentlicht 03.02.2025 04:15:09
- Zuletzt bearbeitet 23.01.2026 18:54:39
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and ...
CVE-2024-41709
- EPSS 0.34%
- Veröffentlicht 22.07.2024 06:15:02
- Zuletzt bearbeitet 21.03.2025 21:15:35
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" pe...
CVE-2022-42094
- EPSS 38.03%
- Veröffentlicht 22.11.2022 13:15:14
- Zuletzt bearbeitet 29.04.2025 15:15:49
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
CVE-2022-42097
- EPSS 0.62%
- Veröffentlicht 22.11.2022 13:15:14
- Zuletzt bearbeitet 29.04.2025 15:15:49
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .
CVE-2022-24590
- EPSS 0.21%
- Veröffentlicht 15.02.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:42
A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML.
CVE-2021-45268
- EPSS 0.45%
- Veröffentlicht 03.02.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:32:03
A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor dispu...
CVE-2019-14769
- EPSS 0.27%
- Veröffentlicht 08.08.2019 02:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:18
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute ...
CVE-2019-11358
- EPSS 1.86%
- Veröffentlicht 20.04.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:56
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the n...