Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Backdropcms

First CVE: Dec 20, 2018Active for: 8 yearsTotal CVEs: 25
37.4
VTI Score
Medium

Backdropcms develops a content-management system and related applications positioned as a community-driven alternative within the CMS landscape. The vendor's vulnerability portfolio, while concentrated in a narrow product line, has accumulated disclosures that recur through application-layer input-handling weaknesses: cross-site scripting, improper input validation, cross-site request forgery, prototype pollution, and open redirects. These classes are characteristic of web application development and reflect the ongoing tension between feature velocity and input-sanitization rigor in PHP-based CMS platforms. Vulnerabilities affecting this vendor frequently acquire public exploit code, creating a meaningful risk for deployed instances that lag on updates. Defenders should monitor Backdropcms advisories for its CMS and related extensions; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Backdropcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2018
7 years ago
Most Recent CVE
Nov 18, 2025
248 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11358MEDIUM
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
CVE-2019-14771CRITICAL
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficien
Aug 8, 20199.830NONO
CVE-2022-42095MEDIUM
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
Nov 23, 20224.828NOYES
CVE-2022-42096MEDIUM
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
Nov 21, 20224.828NOYES
CVE-2021-45268HIGH
A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via upload
Feb 3, 20228.828NONO
CVE-2022-42092HIGH
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced
Oct 7, 20227.225NONO
CVE-2025-25062MEDIUM
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is
Feb 3, 20254.424NOYES
CVE-2019-19902HIGH
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or comm
Dec 19, 20197.223NONO
CVE-2022-42094MEDIUM
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
Nov 22, 20224.822NOYES
CVE-2025-63828MEDIUM
Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and
Nov 18, 20256.121NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
84%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None4 (16.0%)
Unknown0 (0.0%)
Required21 (84.0%)
Privileges Required
Low3 (12.0%)
High12 (48.0%)
None10 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
16.0% of CVEs· 97th percentile
ExploitDB
1 CVE
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Backdropcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Backdropcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Backdropcms's Products

View all 2 CNAs →

Top CWEs