XSS Vulnerability in Backdrop CMS Versions Prior to 1.28.5 and 1.29.3
CVE-2025-25063
4.4MEDIUM
What is CVE-2025-25063?
An XSS vulnerability exists in Backdrop CMS versions 1.28.x prior to 1.28.5 and 1.29.x prior to 1.29.3, due to insufficient validation of uploaded SVG images. Attackers can potentially exploit this flaw by uploading specially crafted SVG files containing dangerous scripts. While exploitation requires the attacker to upload the SVG, and Backdrop CMS embeds these images in <img> tags which limits execution, any direct access to the SVG via its URL could lead to script execution in the browser. It is crucial for users to update their Backdrop CMS to the latest versions to mitigate this security risk.
Affected Version(s)
backdrop 1.28.0 < 1.28.5
backdrop 1.29.0 < 1.29.3