Skip to main content

Vendor/product archive

backdropcms / backdrop CVEs

Beta · best-effort

7 CVEs tagged to backdropcms / backdrop0 Critical, 1 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-41709

Published Jul 22, 2024

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42097

Published Nov 22, 2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42094

Published Nov 22, 2022

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24590

Published Feb 15, 2022

A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45268

Published Feb 3, 2022

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14769

Published Aug 8, 2019

Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could pot…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1