First published: Fri Mar 07 2025(Updated: )
An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Backdrop Lite | <1.x-1.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27826 has been classified as a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2025-27826, update your Backdrop CMS Lite theme to version 1.x-1.4.5 or later.
CVE-2025-27826 affects the Bootstrap Lite theme for Backdrop CMS versions prior to 1.x-1.4.5.
CVE-2025-27826 is an XSS (Cross-Site Scripting) vulnerability due to inadequate sanitization of class names.
If CVE-2025-27826 is exploited, it could allow attackers to execute malicious scripts in the context of the affected user’s session.