CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2025-71310 LOW

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been…

CVSS 1.8 EPSS 0.26% May 26, 2026
CVE-2025-63828 MEDIUM

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to m…

CVSS 6.9 EPSS 0.21% Nov 18, 2025
CVE-2025-44141 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

CVSS 6.1 EPSS 0.21% Jun 26, 2025
CVE-2025-46595 MEDIUM

An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and…

CVSS 6.4 EPSS 0.24% Apr 25, 2025
CVE-2025-27826 MEDIUM

An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.

CVSS 6.4 EPSS 0.24% Mar 7, 2025
CVE-2025-27825 MEDIUM

An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.

CVSS 6.4 EPSS 0.24% Mar 7, 2025
CVE-2025-27824 MEDIUM

An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficiently sanitize input before displaying res…

CVSS 6.4 EPSS 0.24% Mar 7, 2025
CVE-2025-27823 MEDIUM

An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdrop CMS. It enables a website to obfuscate email addresses, and should prevent sp…

CVSS 6.4 EPSS 0.24% Mar 7, 2025
CVE-2025-27822 HIGH

An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. The module…

CVSS 7.5 EPSS 0.30% Mar 7, 2025
CVE-2025-25063 MEDIUM

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they…

CVSS 4.4 EPSS 0.20% Feb 3, 2025
CVE-2025-25062 MEDIUM

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor…

CVSS 4.4 EPSS 1.72% Feb 3, 2025
CVE-2024-54123 MEDIUM

Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

CVSS 6.1 EPSS 0.29% Nov 29, 2024
CVE-2024-41709 MEDIUM

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability…

CVSS 4.6 EPSS 0.32% Jul 22, 2024
CVE-2023-31045 MEDIUM

A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or H…

CVSS 4.8 EPSS 0.53% Apr 24, 2023
CVE-2012-10004 MEDIUM

backdrop-contrib Basic Cart basic_cart.cart.inc basic_cart_checkout_form_submit cross site scripting

CVSS 6.1 EPSS 0.52% Jan 11, 2023
CVE-2022-42095 MEDIUM

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

CVSS 4.8 EPSS 2.08% Nov 23, 2022
CVE-2022-42097 MEDIUM

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .

CVSS 4.8 EPSS 0.83% Nov 22, 2022
CVE-2022-42094 MEDIUM

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.

CVSS 4.8 EPSS 2.68% Nov 22, 2022
CVE-2022-42096 MEDIUM

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

CVSS 4.8 EPSS 2.09% Nov 21, 2022
CVE-2022-42092 HIGH

Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this an…

CVSS 7.2 EPSS 1.65% Oct 7, 2022
CVE-2022-34530 MEDIUM

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct…

CVSS 5.3 EPSS 0.62% Aug 1, 2022
CVE-2022-24590 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML.

CVSS 5.4 EPSS 0.62% Feb 15, 2022
CVE-2021-45268 HIGH

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting…

CVSS 8.8 EPSS 1.82% Feb 3, 2022
CVE-2019-19900 MEDIUM

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names…

CVSS 4.8 EPSS 0.55% Dec 19, 2019
CVE-2019-19902 HIGH

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the u…

CVSS 7.2 EPSS 1.50% Dec 19, 2019

Showing 1 to 25 CVEs · page 1 (more available)