Backdropcms develops a content-management system and related applications positioned as a community-driven alternative within the CMS landscape. The vendor's vulnerability portfolio, while concentrated in a narrow product line, has accumulated disclosures that recur through application-layer input-handling weaknesses: cross-site scripting, improper input validation, cross-site request forgery, prototype pollution, and open redirects. These classes are characteristic of web application development and reflect the ongoing tension between feature velocity and input-sanitization rigor in PHP-based CMS platforms. Vulnerabilities affecting this vendor frequently acquire public exploit code, creating a meaningful risk for deployed instances that lag on updates. Defenders should monitor Backdropcms advisories for its CMS and related extensions; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Backdropcms over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11358MEDIUM jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob | Apr 20, 2019 | 6.1 | 78 | NO | YES |
CVE-2019-14771CRITICAL Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficien | Aug 8, 2019 | 9.8 | 30 | NO | NO |
CVE-2022-42095MEDIUM Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content. | Nov 23, 2022 | 4.8 | 28 | NO | YES |
CVE-2022-42096MEDIUM Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content. | Nov 21, 2022 | 4.8 | 28 | NO | YES |
CVE-2021-45268HIGH A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via upload | Feb 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-42092HIGH Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced | Oct 7, 2022 | 7.2 | 25 | NO | NO |
CVE-2025-25062MEDIUM An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is | Feb 3, 2025 | 4.4 | 24 | NO | YES |
CVE-2019-19902HIGH An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or comm | Dec 19, 2019 | 7.2 | 23 | NO | NO |
CVE-2022-42094MEDIUM Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content. | Nov 22, 2022 | 4.8 | 22 | NO | YES |
CVE-2025-63828MEDIUM Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and | Nov 18, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Backdropcms.
Media articles that mention a CVE ID that affects a product developed by Backdropcms — matched by CVE ID, not by vendor name.