CVE-2025-63828
- EPSS 0.03%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 24.11.2025 14:02:35
Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.
CVE-2025-44141
- EPSS 0.02%
- Veröffentlicht 26.06.2025 00:00:00
- Zuletzt bearbeitet 01.07.2025 16:03:07
A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.
CVE-2024-54123
- EPSS 0.09%
- Veröffentlicht 29.11.2024 04:15:03
- Zuletzt bearbeitet 29.11.2024 19:15:10
Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.
CVE-2022-42095
- EPSS 53.15%
- Veröffentlicht 23.11.2022 02:15:10
- Zuletzt bearbeitet 28.04.2025 18:15:44
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
CVE-2022-42096
- EPSS 21.35%
- Veröffentlicht 21.11.2022 21:15:11
- Zuletzt bearbeitet 29.04.2025 20:15:21
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
CVE-2022-42092
- EPSS 1.73%
- Veröffentlicht 07.10.2022 18:15:23
- Zuletzt bearbeitet 21.11.2024 07:24:21
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.
CVE-2022-34530
- EPSS 0.2%
- Veröffentlicht 01.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:09:42
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
CVE-2019-19901
- EPSS 0.41%
- Veröffentlicht 19.12.2019 06:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:37
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized descr...
CVE-2019-19902
- EPSS 0.61%
- Veröffentlicht 19.12.2019 06:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:37
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid...
CVE-2019-19903
- EPSS 0.41%
- Veröffentlicht 19.12.2019 06:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:37
An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administ...