S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Web Vulnerabilities·Updated Feb 24, 2025

CVE-2025-25062 Scanner

CVE-2025-25062 Scanner - Cross-Site Scripting (XSS) vulnerability in Backdrop CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-25062
4.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attacker must have the ability to create long text content (such as through the node or comment forms) and an administrator must edit (not view) the content that contains the malicious content. This problem only exists when using the CKEditor 5 module.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
backdropby backdropcms
AFFECTED< 1.28.5SAFE ✓≥ 1.28.5
Updated Sep 9, 2026View on NVD →
Detail

Backdrop CMS is a content management system widely employed for building and managing websites and web applications. Developers and administrators utilize it to create and maintain online platforms, taking advantage of its extensive functionalities and user-friendly nature. The platform supports organizational and individual needs, allowing for the customization and extension of web projects through modules and layouts. However, Backdrop CMS users may confront security risks if their platform versions fall behind on patches, making updates and vigilant security assessments critical. Regular monitoring and usage of tools like security scanners help in identifying vulnerabilities early, thus preserving the integrity and security of web operations. Specifically, ensuring that plugins and editors like CKEditor used within the CMS are updated can significantly safeguard against known vulnerabilities.

Cross-Site Scripting (XSS) is a vulnerability allowing attackers to inject malicious scripts into web pages viewed by other users. In the context of Backdrop CMS, this vulnerability arises in conjunction with the usage of the CKEditor 5 module, permitting potential script execution during content editing. The susceptibility exists because the platform does not adequately isolate long text content in specific editor configurations. This makes it imperative for administrators to be cautious with user-generated content, especially when dealing with untrusted sources. Preventative measures, including input sanitization and regular CMS updates, are vital in mitigating XSS risks. The severity is reduced by requiring an attacker to possess specific content creation capabilities and necessitating administrative interaction with the malicious content.

In technical terms, the vulnerability is found within Backdrop CMS versions prior to 1.28.5 and 1.29.3, impacting sites employing CKEditor 5 for rich text editing. The platform fails to isolate long text entries adequately, allowing injected HTML and JavaScript to be executed under certain conditions. Vulnerable endpoints include the URLs for creating and editing content nodes where malicious scripts can be embedded. Parameters and fields utilized in content forms are potential vectors for XSS payloads. Malicious scripts execute when an administrator interacts with a compromised content piece, notably during editing rather than merely viewing. As the exploit requires specific circumstances, the CVSS score reflects a medium risk, yet it's crucial for responsible maintenance and timely updates.

When exploited, this XSS vulnerability could lead to unauthorized actions being performed by unsuspecting users or administrators within the Backdrop CMS. Attackers could gain access to certain data or controls by masquerading scripts as legitimate processes through crafted payloads. The CMS's susceptibility provides a platform for escalating privileges, stealing session cookies, or performing actions representing legitimate users. It may result in website defacement, user redirection to malicious sites, or collection of sensitive data, hence posing financial and reputational risks. To mitigate these consequences, administrators should ensure their CMS installations are updated and security best practices are consistently applied.

REFERENCES

Solution Advice
  • Upgrade Backdrop CMS to version 1.28.5, 1.29.3, or later to patch the identified vulnerability.
  • Implement strict input validation and sanitization on user-generated content, particularly in rich text fields.
  • Regularly review and update all installed modules and plugins, ensuring they are from trusted sources.
  • Restrict permissions for content creation to trusted users and enhance monitoring for unauthorized activities.
  • Enable Content Security Policy (CSP) to mitigate the impact of possible script injection scenarios.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-25062 Scanner - Cross-Site Scripting (XSS) vulnerability in Backdrop CMS | S4E