Backdropcms

Backdrop Cms

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 18.11.2025 00:00:00
  • Zuletzt bearbeitet 24.11.2025 14:02:35

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.

  • EPSS 0.05%
  • Veröffentlicht 26.06.2025 00:00:00
  • Zuletzt bearbeitet 04.03.2026 18:45:26

A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

Exploit
  • EPSS 24.64%
  • Veröffentlicht 03.02.2025 04:15:09
  • Zuletzt bearbeitet 23.01.2026 18:46:32

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and ...

  • EPSS 0.61%
  • Veröffentlicht 03.02.2025 04:15:09
  • Zuletzt bearbeitet 23.01.2026 18:54:39

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and ...

  • EPSS 0.42%
  • Veröffentlicht 29.11.2024 04:15:03
  • Zuletzt bearbeitet 06.04.2026 14:08:56

Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 24.04.2023 08:15:07
  • Zuletzt bearbeitet 06.04.2026 13:45:57

A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via the name parameter. When a user is editing any content type (e.g., page, post, or c...

Exploit
  • EPSS 42.13%
  • Veröffentlicht 23.11.2022 02:15:10
  • Zuletzt bearbeitet 28.04.2025 18:15:44

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

Exploit
  • EPSS 21.35%
  • Veröffentlicht 21.11.2022 21:15:11
  • Zuletzt bearbeitet 29.04.2025 20:15:21

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

Exploit
  • EPSS 1.73%
  • Veröffentlicht 07.10.2022 18:15:23
  • Zuletzt bearbeitet 21.11.2024 07:24:21

Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.

  • EPSS 0.21%
  • Veröffentlicht 01.08.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:09:42

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.