Skip to content
Noroxi

backdropcms records

25 published records for vendor backdropcms.

All records

25 records
  • jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp

    MediumCVSS 6.1Proof of conceptEPSS 87%

    jquery · jqueryApr 19, 2019

  • Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interfac

    CriticalCVSS 9.8No exploitEPSS 3%

    backdropcms · backdrop cmsAug 7, 2019

  • A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (

    HighCVSS 8.8No exploitEPSS 2%

    backdropcms · backdropFeb 3, 2022

  • Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution.

    HighCVSS 7.2Proof of conceptEPSS 2%

    backdropcms · backdrop cmsOct 7, 2022

  • An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.

    HighCVSS 7.2No exploitEPSS 1%

    backdropcms · backdrop cmsDec 19, 2019

  • Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created b

    MediumCVSS 6.1No exploitEPSS 1%

    backdropcms · backdropAug 7, 2019

  • In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaS

    MediumCVSS 6.1No exploitEPSS 1%

    backdropcms · backdrop coreAug 7, 2019

  • backdrop-contrib Basic Cart basic_cart.cart.inc basic_cart_checkout_form_submit cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    backdropcms · basic cartJan 11, 2023

  • Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

    MediumCVSS 6.1No exploitEPSS 0%

    backdropcms · backdrop cmsNov 29, 2024

  • A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

    MediumCVSS 6.1No exploitEPSS 0%

    backdropcms · backdrop cmsJun 26, 2025

  • Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leadin

    MediumCVSS 6.1No exploitEPSS 0%

    backdropcms · backdrop cmsNov 18, 2025

  • A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web

    MediumCVSS 5.4No exploitEPSS 1%

    backdropcms · backdropFeb 15, 2022

  • An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset re

    MediumCVSS 5.3No exploitEPSS 1%

    backdropcms · backdrop cmsAug 1, 2022

  • Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.

    MediumCVSS 4.8Proof of conceptEPSS 3%

    backdropcms · backdropNov 22, 2022

  • Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

    MediumCVSS 4.8Proof of conceptEPSS 2%

    backdropcms · backdrop cmsNov 21, 2022

  • Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

    MediumCVSS 4.8Proof of conceptEPSS 2%

    backdropcms · backdrop cmsNov 22, 2022

  • Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .

    MediumCVSS 4.8Proof of conceptEPSS 1%

    backdropcms · backdropNov 22, 2022

  • Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on bl

    MediumCVSS 4.8No exploitEPSS 1%

    backdropcms · backdrop cmsDec 20, 2018

  • An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.

    MediumCVSS 4.8No exploitEPSS 1%

    backdropcms · backdrop cmsDec 19, 2019

  • An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.

    MediumCVSS 4.8No exploitEPSS 1%

    backdropcms · backdrop cmsDec 19, 2019

  • An issue was discovered in Backdrop CMS 1.14.x before 1.14.2.

    MediumCVSS 4.8No exploitEPSS 1%

    backdropcms · backdrop cmsDec 19, 2019

  • A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitr

    MediumCVSS 4.8No exploitEPSS 1%

    backdropcms · backdrop cmsApr 24, 2023

  • Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places.

    MediumCVSS 4.8No exploitEPSS 0%

    backdropcms · backdropJul 22, 2024

  • An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3.

    MediumCVSS 4.4Proof of conceptEPSS 2%

    backdropcms · backdrop cmsFeb 3, 2025

  • An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3.

    MediumCVSS 4.4No exploitEPSS 0%

    backdropcms · backdrop cmsFeb 3, 2025