Vulnerabilities
Vulnerable Software
Backdropcms:  >> Backdrop  >> 1.28.1  Security Vulnerabilities
Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.
CVSS Score
6.1
EPSS Score
0.004
Published
2024-11-29
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
CVSS Score
4.8
EPSS Score
0.003
Published
2024-07-22


Contact Us

Shodan ® - All rights reserved