<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Backdrop</title>
  <link>https://cvedaily.com/pages/tags/backdrop.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/backdrop.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Backdrop</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:43 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2025-71310 – The GDPR cookies module for Backdrop CMS (before 

1.x-1.3.5) doesn't sufficient...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-71310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-71310</guid>
    <pubDate>Tue, 26 May 2026 02:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-71310</strong></p>
  <p>The GDPR cookies module for Backdrop CMS (before   1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site mus…</p>
  <p><strong>CVSS:</strong> 1.8 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-71310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45430 – The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45430</guid>
    <pubDate>Tue, 12 May 2026 04:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45430</strong></p>
  <p>The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-63828 – Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63828</guid>
    <pubDate>Tue, 18 Nov 2025 18:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-63828</strong></p>
  <p>Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-44141 – A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44141</guid>
    <pubDate>Thu, 26 Jun 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-44141</strong></p>
  <p>A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-46595 – An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46595</guid>
    <pubDate>Fri, 25 Apr 2025 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-46595</strong></p>
  <p>An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module. This can allow crafted HTML to result in Cross Site Scripting. This is mitigate…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27826 – An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Bac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27826</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27826</strong></p>
  <p>An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27825 – An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27825</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27825</strong></p>
  <p>An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27824 – An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27824</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27824</strong></p>
  <p>An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficiently sanitize input before displaying results to the screen. This vulnerability is mitigated by the fact that an attacker must have the ability to create content containing an iFrame field.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27823 – An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27823</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27823</strong></p>
  <p>An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdrop CMS. It enables a website to obfuscate email addresses, and should prevent spambots from collecting them. The module doesn't sufficiently validate the data attribute value on links, potentially leading to a Cross Site Scripting (XSS) vulnerability. This is mitigated by the fact an attacker must be able to insert lin…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27822 – An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27822</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27822</strong></p>
  <p>An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. The module provides a "Masquerade as admin" permission to restrict people (who can masquerade) from switching to an account with administrative privileges. This permission is not always honored and may allow non-administrative users to masquerade as a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25063 – An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25063</guid>
    <pubDate>Mon, 03 Feb 2025 04:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25063</strong></p>
  <p>An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and executable scripting, and using a crafted SVG, it is possible to execute scripting in the browser when an SVG image is viewed. This issue is mitigate…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25062 – An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25062</guid>
    <pubDate>Mon, 03 Feb 2025 04:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25062</strong></p>
  <p>An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attack…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-54123 – Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG docume...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54123</guid>
    <pubDate>Fri, 29 Nov 2024 04:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-54123</strong></p>
  <p>Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41709 – Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently saniti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41709</guid>
    <pubDate>Mon, 22 Jul 2024 06:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41709</strong></p>
  <p>Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-31045 – A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31045</guid>
    <pubDate>Mon, 24 Apr 2023 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-31045</strong></p>
  <p>A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via the name parameter. When a user is editing any content type (e.g., page, post, or card) as an admin, the stored XSS payload is executed upon selecting a malicious text formatting option. NOTE: the vendor disputes the security releva…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26265 – The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26265</guid>
    <pubDate>Tue, 21 Feb 2023 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26265</strong></p>
  <p>The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly sanitize incoming path arguments before using them.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2012-10004 – A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-10004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-10004</guid>
    <pubDate>Wed, 11 Jan 2023 07:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2012-10004</strong></p>
  <p>A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basic_cart_checkout_form_submit of the file basic_cart.cart.inc. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.x-1.1.1 is able to address this issue. The patch is identified as a10424ccd4b3b4b433c…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-10004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-42095 – Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42095</guid>
    <pubDate>Wed, 23 Nov 2022 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-42095</strong></p>
  <p>Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-42097 – Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42097</guid>
    <pubDate>Tue, 22 Nov 2022 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-42097</strong></p>
  <p>Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-42094 – Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42094</guid>
    <pubDate>Tue, 22 Nov 2022 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-42094</strong></p>
  <p>Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-42096 – Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42096</guid>
    <pubDate>Mon, 21 Nov 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-42096</strong></p>
  <p>Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-42092 – Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42092</guid>
    <pubDate>Fri, 07 Oct 2022 18:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-42092</strong></p>
  <p>Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-34530 – An issue in the login and reset password functionality of Backdrop CMS v1.22.0 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34530</guid>
    <pubDate>Mon, 01 Aug 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-34530</strong></p>
  <p>An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45268 – A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45268</guid>
    <pubDate>Thu, 03 Feb 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45268</strong></p>
  <p>A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack requires a session cookie of a high-privileged authenticated user who is entitled to install arbitrary add-ons</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19903 – An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't suffici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19903</guid>
    <pubDate>Thu, 19 Dec 2019 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19903</strong></p>
  <p>An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when viewing the list of file types, aka XSS. This vulnerability is mitigated by the fact that an attacker must have a role w…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19902 – An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19902</guid>
    <pubDate>Thu, 19 Dec 2019 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19902</strong></p>
  <p>An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be re…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19901 – An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19901</guid>
    <pubDate>Thu, 19 Dec 2019 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19901</strong></p>
  <p>An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring a layout, aka XSS. This issue is mitigated by the fact that the attacker would…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19900 – An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19900</guid>
    <pubDate>Thu, 19 Dec 2019 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19900</strong></p>
  <p>An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An attacker could potentially craft a specialized content type name, then have an editor execute scripting when creating content, aka XSS. This vulnerability is mitigated by the fact that an attacker must…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-14771 – Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14771</guid>
    <pubDate>Thu, 08 Aug 2019 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-14771</strong></p>
  <p>Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be uploaded to the server. (This attack is mitigated by the attacker needing the "Synchronize, import, and export configura…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14770 – In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14770</guid>
    <pubDate>Thu, 08 Aug 2019 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14770</strong></p>
  <p>In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (This issue is mitigated by the attacker needing permissions to create administrative menu links, such as by creating a content type or layout. Such permissions are usually restricte…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14769 – Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14769</guid>
    <pubDate>Thu, 08 Aug 2019 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14769</strong></p>
  <p>Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout. (This issue is mitigated by the attacker needing permission to create custom blocks on the site, which is typi…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-11358 – jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11358</guid>
    <pubDate>Sat, 20 Apr 2019 00:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-11358</strong></p>
  <p>jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1000813 – Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000813</guid>
    <pubDate>Thu, 20 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1000813</strong></p>
  <p>Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected source.. This attack appear to be exploitable via A user must be directed to an affected page while logged in.. This vulnerability appears to have been fixed in 1.11.1 and later.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000813">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
