Skip to main content

Vendor archive

backdropcms CVEs

Beta · best-effort

25 CVEs tagged to vendor backdropcms1 Critical, 3 High, 20 Medium, 1 Low, 0 Unrated.

CVE-2025-63828

Published Nov 18, 2025

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25063

Published Feb 3, 2025

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain pote…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-25062

Published Feb 3, 2025

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor i…

CVSS 4.4 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-54123

Published Nov 29, 2024

Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41709

Published Jul 22, 2024

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31045

Published Apr 24, 2023

A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via the name par…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-10004

Published Jan 11, 2023

A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basic_cart_checkout_form_submit of the file bas…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-42095

Published Nov 23, 2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42097

Published Nov 22, 2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42094

Published Nov 22, 2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42096

Published Nov 21, 2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42092

Published Oct 7, 2022

Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advance…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34530

Published Aug 1, 2022

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24590

Published Feb 15, 2022

A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45268

Published Feb 3, 2022

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19903

Published Dec 19, 2019

An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker c…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19902

Published Dec 19, 2019

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or com…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19901

Published Dec 19, 2019

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19900

Published Dec 19, 2019

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content crea…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14771

Published Aug 8, 2019

Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficie…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14770

Published Aug 8, 2019

In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14769

Published Aug 8, 2019

Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could pot…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000813

Published Dec 20, 2018

Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Ex…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1