<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Backdrop (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/backdrop.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/backdrop-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Backdrop (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:43 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-45430 – The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45430</guid>
    <pubDate>Tue, 12 May 2026 04:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45430</strong></p>
  <p>The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27822 – An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27822</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27822</strong></p>
  <p>An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. The module provides a "Masquerade as admin" permission to restrict people (who can masquerade) from switching to an account with administrative privileges. This permission is not always honored and may allow non-administrative users to masquerade as a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42092 – Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42092</guid>
    <pubDate>Fri, 07 Oct 2022 18:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42092</strong></p>
  <p>Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45268 – A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45268</guid>
    <pubDate>Thu, 03 Feb 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45268</strong></p>
  <p>A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack requires a session cookie of a high-privileged authenticated user who is entitled to install arbitrary add-ons</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19902 – An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19902</guid>
    <pubDate>Thu, 19 Dec 2019 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19902</strong></p>
  <p>An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be re…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-14771 – Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14771</guid>
    <pubDate>Thu, 08 Aug 2019 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-14771</strong></p>
  <p>Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be uploaded to the server. (This attack is mitigated by the attacker needing the "Synchronize, import, and export configura…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14771">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
