First published: Fri Mar 07 2025(Updated: )
An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Backdrop | <1.x-1.0.3 | |
Bootstrap 5 Lite theme | <1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27825 has been assigned a high severity rating due to its potential to allow reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-27825, upgrade to Backdrop CMS version 1.x-1.0.3 or later.
CVE-2025-27825 addresses an XSS vulnerability in the Bootstrap 5 Lite theme that fails to properly sanitize dynamic class names.
CVE-2025-27825 affects users of the Bootstrap 5 Lite theme in Backdrop CMS versions before 1.x-1.0.3.
There are no official workarounds for CVE-2025-27825; upgrading is the recommended solution.