S4E just found a high-severity finding from [ai] pa ssl inspection control
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-25062

4.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.
Description

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attacker must have the ability to create long text content (such as through the node or comment forms) and an administrator must edit (not view) the content that contains the malicious content. This problem only exists when using the CKEditor 5 module.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
backdrop
Updated Sep 28, 2026View on NVD →
S4E scanner
mediumWeb Vulnerabilities~10 seconds

CVE-2025-25062 Scanner

CVE-2025-25062 Scanner - Cross-Site Scripting (XSS) vulnerability in Backdrop CMS

Used 2.5k times · 3.3k assets checked · domain, subdomain, ipv4

CVE history: backdrop

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →