CVE-2025-44141
- EPSS 0.04%
- Published 26.06.2025 00:00:00
- Last modified 01.07.2025 16:03:07
A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.
CVE-2024-54123
- EPSS 0.09%
- Published 29.11.2024 04:15:03
- Last modified 29.11.2024 19:15:10
Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.
CVE-2022-42095
- EPSS 43.36%
- Published 23.11.2022 02:15:10
- Last modified 28.04.2025 18:15:44
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
CVE-2022-42096
- EPSS 14.95%
- Published 21.11.2022 21:15:11
- Last modified 29.04.2025 20:15:21
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
CVE-2022-42092
- EPSS 0.71%
- Published 07.10.2022 18:15:23
- Last modified 21.11.2024 07:24:21
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.
CVE-2022-34530
- EPSS 0.2%
- Published 01.08.2022 20:15:08
- Last modified 21.11.2024 07:09:42
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
CVE-2019-19901
- EPSS 0.41%
- Published 19.12.2019 06:15:11
- Last modified 21.11.2024 04:35:37
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized descr...
CVE-2019-19902
- EPSS 0.61%
- Published 19.12.2019 06:15:11
- Last modified 21.11.2024 04:35:37
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid...
CVE-2019-19903
- EPSS 0.41%
- Published 19.12.2019 06:15:11
- Last modified 21.11.2024 04:35:37
An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administ...
CVE-2019-19900
- EPSS 0.41%
- Published 19.12.2019 06:15:10
- Last modified 21.11.2024 04:35:37
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An attacker could potentially craft a specialized conte...