Backdropcms / Backdrop Cms
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-63828 | Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to m… | MEDIUM | 6.9 | Nov 18, 2025 |
| CVE-2025-44141 | A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30. | MEDIUM | 6.1 | Jun 26, 2025 |
| CVE-2025-25063 | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they… | MEDIUM | 4.4 | Feb 3, 2025 |
| CVE-2025-25062 | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor… | MEDIUM | 4.4 | Feb 3, 2025 |
| CVE-2024-54123 | Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format. | MEDIUM | 6.1 | Nov 29, 2024 |
| CVE-2023-31045 | A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or H… | MEDIUM | 4.8 | Apr 24, 2023 |
| CVE-2022-42095 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content. | MEDIUM | 4.8 | Nov 23, 2022 |
| CVE-2022-42096 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content. | MEDIUM | 4.8 | Nov 21, 2022 |
| CVE-2022-42092 | Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this an… | HIGH | 7.2 | Oct 7, 2022 |
| CVE-2022-34530 | An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct… | MEDIUM | 5.3 | Aug 1, 2022 |
| CVE-2019-19900 | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names… | MEDIUM | 4.8 | Dec 19, 2019 |
| CVE-2019-19902 | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the u… | HIGH | 7.2 | Dec 19, 2019 |
| CVE-2019-19903 | An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administr… | MEDIUM | 4.8 | Dec 19, 2019 |
| CVE-2019-19901 | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block desc… | MEDIUM | 4.8 | Dec 19, 2019 |
| CVE-2019-14771 | Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line.… | CRITICAL | 9.8 | Aug 8, 2019 |
| CVE-2018-1000813 | Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. t… | MEDIUM | 4.8 | Dec 20, 2018 |
Showing 1 to 16 of 16 CVEs