XSS Vulnerability in Backdrop CMS Versions Prior to 1.28.5 and 1.29.3
CVE-2025-25063
What is CVE-2025-25063?
An XSS vulnerability exists in Backdrop CMS versions 1.28.x prior to 1.28.5 and 1.29.x prior to 1.29.3, due to insufficient validation of uploaded SVG images. Attackers can potentially exploit this flaw by uploading specially crafted SVG files containing dangerous scripts. While exploitation requires the attacker to upload the SVG, and Backdrop CMS embeds these images in <img> tags which limits execution, any direct access to the SVG via its URL could lead to script execution in the browser. It is crucial for users to update their Backdrop CMS to the latest versions to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
backdrop 1.28.0 < 1.28.5
backdrop 1.29.0 < 1.29.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
