Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Low
CVE-2019-11358
Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
6
Attacker Value
Unknown
CVE-2024-41709
Disclosure Date: July 22, 2024 (last updated February 26, 2025)
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
0
Attacker Value
Unknown
CVE-2023-31045
Disclosure Date: April 24, 2023 (last updated February 24, 2025)
A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via the name parameter. When a user is editing any content type (e.g., page, post, or card) as an admin, the stored XSS payload is executed upon selecting a malicious text formatting option. NOTE: the vendor disputes the security relevance of this finding because "any administrator that can configure a text format could easily allow Full HTML anywhere."
0
Attacker Value
Unknown
CVE-2022-42095
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
0
Attacker Value
Unknown
CVE-2022-42094
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
0
Attacker Value
Unknown
CVE-2022-42097
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .
0
Attacker Value
Unknown
CVE-2022-42096
Disclosure Date: November 21, 2022 (last updated February 24, 2025)
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
0
Attacker Value
Unknown
CVE-2022-42092
Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.
0
Attacker Value
Unknown
CVE-2022-34530
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
0
Attacker Value
Unknown
CVE-2022-24590
Disclosure Date: February 15, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML.
0