Backdropcms

Backdrop Cms

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 18.11.2025 00:00:00
  • Zuletzt bearbeitet 24.11.2025 14:02:35

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.

  • EPSS 0.03%
  • Veröffentlicht 26.06.2025 00:00:00
  • Zuletzt bearbeitet 01.07.2025 16:03:07

A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

Exploit
  • EPSS 42.84%
  • Veröffentlicht 03.02.2025 04:15:09
  • Zuletzt bearbeitet 23.01.2026 18:46:32

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and ...

  • EPSS 0.2%
  • Veröffentlicht 03.02.2025 04:15:09
  • Zuletzt bearbeitet 23.01.2026 18:54:39

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and ...

  • EPSS 0.32%
  • Veröffentlicht 29.11.2024 04:15:03
  • Zuletzt bearbeitet 26.01.2026 15:51:32

Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

Exploit
  • EPSS 42.13%
  • Veröffentlicht 23.11.2022 02:15:10
  • Zuletzt bearbeitet 28.04.2025 18:15:44

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

Exploit
  • EPSS 21.35%
  • Veröffentlicht 21.11.2022 21:15:11
  • Zuletzt bearbeitet 29.04.2025 20:15:21

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

Exploit
  • EPSS 1.73%
  • Veröffentlicht 07.10.2022 18:15:23
  • Zuletzt bearbeitet 21.11.2024 07:24:21

Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.

  • EPSS 0.21%
  • Veröffentlicht 01.08.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:09:42

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.

  • EPSS 0.41%
  • Veröffentlicht 19.12.2019 06:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:37

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized descr...