Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Backdrop Cms MEDIUM 6.1
CVE-2025-63828

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redi…

No fix yet
Fix from $1,600 2025-11-18
Backdrop Cms MEDIUM 6.1
CVE-2025-44141

A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

Mitigation only
Fix from $1,600 2025-06-26
Backdrop Cms MEDIUM 6.1
CVE-2024-54123

Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

Fix: 1.28.4 / 1.29.2+
Fix from $1,600 2024-11-29
Basic Cart MEDIUM 6.1
CVE-2012-10004

A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basic_cart_checko…

Fix: 1.x-1.1.1+
Fix from $1,600 2023-01-11
Backdrop Cms HIGH 7.2
CVE-2022-42092

Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispu…

No fix yet
Fix from $1,950 2022-10-07
Backdrop Cms MEDIUM 5.3
CVE-2022-34530

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests an…

Fix: after 1.22.0
Fix from $1,600 2022-08-01
Backdrop MEDIUM 5.4
CVE-2022-24590

A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts o…

No fix yet
Fix from $1,600 2022-02-15
Backdrop HIGH 8.8
CVE-2021-45268

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on t…

No fix yet
Fix from $1,950 2022-02-03
Backdrop Cms HIGH 7.2
CVE-2019-19902

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives thr…

Fix: 1.13.5 / 1.14.2+
Fix from $1,950 2019-12-19
Backdrop Cms CRITICAL 9.8
CVE-2019-14771

Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or comm…

Fix: 1.12.8 / 1.13.3+
Fix from $2,300 2019-08-08
Backdrop MEDIUM 6.1
CVE-2019-14769

Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by adminis…

Fix: 1.12.8 / 1.13.3+
Fix from $1,600 2019-08-08
Backdrop Core MEDIUM 6.1
CVE-2019-14770

In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript whe…

Fix: 1.12.8 / 1.13.3+
Fix from $1,600 2019-08-08