backdropcms records
25 published records for vendor backdropcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 28%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-20 Improper Input Validation2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2019-11358Proof of concept | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Medium6.1 | — | 87.2% | Apr 19, 2019 |
40Plan | CVE-2019-14771No exploit | Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interfacbackdropcms · backdrop cms · CWE-20 | Critical9.8 | — | 2.6% | Aug 7, 2019 |
36Monitor | CVE-2021-45268No exploit | A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (backdropcms · backdrop · CWE-352 | High8.8 | — | 1.8% | Feb 3, 2022 |
28Monitor | CVE-2022-42092Proof of concept | Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution.backdropcms · backdrop cms · CWE-434 | High7.2 | — | 1.7% | Oct 7, 2022 |
28Monitor | CVE-2019-19902No exploit | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.backdropcms · backdrop cms · CWE-20 | High7.2 | — | 1.5% | Dec 19, 2019 |
24Monitor | CVE-2019-14769No exploit | Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created bbackdropcms · backdrop · CWE-79 | Medium6.1 | — | 0.8% | Aug 7, 2019 |
24Monitor | CVE-2019-14770No exploit | In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaSbackdropcms · backdrop core · CWE-79 | Medium6.1 | — | 0.8% | Aug 7, 2019 |
24Monitor | CVE-2012-10004No exploit | backdrop-contrib Basic Cart basic_cart.cart.inc basic_cart_checkout_form_submit cross site scriptingbackdropcms · basic cart · CWE-79 | Medium6.1 | — | 0.5% | Jan 11, 2023 |
24Monitor | CVE-2024-54123No exploit | Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.backdropcms · backdrop cms · CWE-79 | Medium6.1 | — | 0.3% | Nov 29, 2024 |
24Monitor | CVE-2025-44141No exploit | A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.backdropcms · backdrop cms · CWE-79 | Medium6.1 | — | 0.2% | Jun 26, 2025 |
24Monitor | CVE-2025-63828No exploit | Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leadinbackdropcms · backdrop cms · CWE-601 | Medium6.1 | — | 0.2% | Nov 18, 2025 |
21Monitor | CVE-2022-24590No exploit | A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web backdropcms · backdrop · CWE-79 | Medium5.4 | — | 0.6% | Feb 15, 2022 |
21Monitor | CVE-2022-34530No exploit | An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset rebackdropcms · backdrop cms · CWE-640 | Medium5.3 | — | 0.6% | Aug 1, 2022 |
20Monitor | CVE-2022-42094Proof of concept | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.backdropcms · backdrop · CWE-79 | Medium4.8 | — | 2.7% | Nov 22, 2022 |
20Monitor | CVE-2022-42096Proof of concept | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.backdropcms · backdrop cms · CWE-79 | Medium4.8 | — | 2.1% | Nov 21, 2022 |
20Monitor | CVE-2022-42095Proof of concept | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.backdropcms · backdrop cms · CWE-79 | Medium4.8 | — | 2.1% | Nov 22, 2022 |
19Monitor | CVE-2022-42097Proof of concept | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .backdropcms · backdrop · CWE-79 | Medium4.8 | — | 0.8% | Nov 22, 2022 |
19Monitor | CVE-2018-1000813No exploit | Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blbackdropcms · backdrop cms · CWE-79 | Medium4.8 | — | 0.7% | Dec 20, 2018 |
19Monitor | CVE-2019-19900No exploit | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.backdropcms · backdrop cms · CWE-79 | Medium4.8 | — | 0.6% | Dec 19, 2019 |
19Monitor | CVE-2019-19901No exploit | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.backdropcms · backdrop cms · CWE-79 | Medium4.8 | — | 0.6% | Dec 19, 2019 |
19Monitor | CVE-2019-19903No exploit | An issue was discovered in Backdrop CMS 1.14.x before 1.14.2.backdropcms · backdrop cms · CWE-79 | Medium4.8 | — | 0.6% | Dec 19, 2019 |
19Monitor | CVE-2023-31045No exploit | A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrbackdropcms · backdrop cms · CWE-79 | Medium4.8 | — | 0.5% | Apr 24, 2023 |
19Monitor | CVE-2024-41709No exploit | Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places.backdropcms · backdrop · CWE-79 | Medium4.8 | — | 0.3% | Jul 22, 2024 |
18Monitor | CVE-2025-25062Proof of concept | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3.backdropcms · backdrop cms · CWE-79 | Medium4.4 | — | 1.7% | Feb 3, 2025 |
17Monitor | CVE-2025-25063No exploit | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3.backdropcms · backdrop cms · CWE-79 | Medium4.4 | — | 0.2% | Feb 3, 2025 |
- CVE-2019-1135850Plan
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
MediumCVSS 6.1Proof of conceptEPSS 87%jquery · jqueryApr 19, 2019
- CVE-2019-1477140Plan
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interfac
CriticalCVSS 9.8No exploitEPSS 3%backdropcms · backdrop cmsAug 7, 2019
- CVE-2021-4526836Monitor
A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (
HighCVSS 8.8No exploitEPSS 2%backdropcms · backdropFeb 3, 2022
- CVE-2022-4209228Monitor
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution.
HighCVSS 7.2Proof of conceptEPSS 2%backdropcms · backdrop cmsOct 7, 2022
- CVE-2019-1990228Monitor
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.
HighCVSS 7.2No exploitEPSS 1%backdropcms · backdrop cmsDec 19, 2019
- CVE-2019-1476924Monitor
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created b
MediumCVSS 6.1No exploitEPSS 1%backdropcms · backdropAug 7, 2019
- CVE-2019-1477024Monitor
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaS
MediumCVSS 6.1No exploitEPSS 1%backdropcms · backdrop coreAug 7, 2019
- CVE-2012-1000424Monitor
backdrop-contrib Basic Cart basic_cart.cart.inc basic_cart_checkout_form_submit cross site scripting
MediumCVSS 6.1No exploitEPSS 1%backdropcms · basic cartJan 11, 2023
- CVE-2024-5412324Monitor
Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.
MediumCVSS 6.1No exploitEPSS 0%backdropcms · backdrop cmsNov 29, 2024
- CVE-2025-4414124Monitor
A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.
MediumCVSS 6.1No exploitEPSS 0%backdropcms · backdrop cmsJun 26, 2025
- CVE-2025-6382824Monitor
Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leadin
MediumCVSS 6.1No exploitEPSS 0%backdropcms · backdrop cmsNov 18, 2025
- CVE-2022-2459021Monitor
A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web
MediumCVSS 5.4No exploitEPSS 1%backdropcms · backdropFeb 15, 2022
- CVE-2022-3453021Monitor
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset re
MediumCVSS 5.3No exploitEPSS 1%backdropcms · backdrop cmsAug 1, 2022
- CVE-2022-4209420Monitor
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
MediumCVSS 4.8Proof of conceptEPSS 3%backdropcms · backdropNov 22, 2022
- CVE-2022-4209620Monitor
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
MediumCVSS 4.8Proof of conceptEPSS 2%backdropcms · backdrop cmsNov 21, 2022
- CVE-2022-4209520Monitor
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
MediumCVSS 4.8Proof of conceptEPSS 2%backdropcms · backdrop cmsNov 22, 2022
- CVE-2022-4209719Monitor
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .
MediumCVSS 4.8Proof of conceptEPSS 1%backdropcms · backdropNov 22, 2022
- CVE-2018-100081319Monitor
Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on bl
MediumCVSS 4.8No exploitEPSS 1%backdropcms · backdrop cmsDec 20, 2018
- CVE-2019-1990019Monitor
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.
MediumCVSS 4.8No exploitEPSS 1%backdropcms · backdrop cmsDec 19, 2019
- CVE-2019-1990119Monitor
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.
MediumCVSS 4.8No exploitEPSS 1%backdropcms · backdrop cmsDec 19, 2019
- CVE-2019-1990319Monitor
An issue was discovered in Backdrop CMS 1.14.x before 1.14.2.
MediumCVSS 4.8No exploitEPSS 1%backdropcms · backdrop cmsDec 19, 2019
- CVE-2023-3104519Monitor
A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitr
MediumCVSS 4.8No exploitEPSS 1%backdropcms · backdrop cmsApr 24, 2023
- CVE-2024-4170919Monitor
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places.
MediumCVSS 4.8No exploitEPSS 0%backdropcms · backdropJul 22, 2024
- CVE-2025-2506218Monitor
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3.
MediumCVSS 4.4Proof of conceptEPSS 2%backdropcms · backdrop cmsFeb 3, 2025
- CVE-2025-2506317Monitor
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3.
MediumCVSS 4.4No exploitEPSS 0%backdropcms · backdrop cmsFeb 3, 2025