Backdropcms / Backdrop
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-25063 | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they… | MEDIUM | 4.4 | Feb 3, 2025 |
| CVE-2025-25062 | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor… | MEDIUM | 4.4 | Feb 3, 2025 |
| CVE-2024-41709 | Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability… | MEDIUM | 4.6 | Jul 22, 2024 |
| CVE-2023-31045 | A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or H… | MEDIUM | 4.8 | Apr 24, 2023 |
| CVE-2022-42097 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' . | MEDIUM | 4.8 | Nov 22, 2022 |
| CVE-2022-42094 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content. | MEDIUM | 4.8 | Nov 22, 2022 |
| CVE-2022-24590 | A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML. | MEDIUM | 5.4 | Feb 15, 2022 |
| CVE-2021-45268 | A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting… | HIGH | 8.8 | Feb 3, 2022 |
| CVE-2019-14769 | Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. A… | MEDIUM | 6.1 | Aug 8, 2019 |
| CVE-2019-11358 | jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection | MEDIUM | 6.1 | Apr 19, 2019 |
Showing 1 to 10 of 10 CVEs