CVE-2025-27824: XSS
An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficiently sanitize input before displaying results to the screen. This vulnerability is mitigated by the fact that an attacker must have the ability to create content containing an iFrame field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27824?
CVE-2025-27824 is classified as a moderate severity vulnerability affecting Backdrop CMS.
How do I fix CVE-2025-27824?
To fix CVE-2025-27824, update the Link iframe formatter module to version 1.x-1.1.1 or later.
What type of vulnerability is CVE-2025-27824?
CVE-2025-27824 is an XSS (Cross-Site Scripting) vulnerability that allows untrusted input to be displayed without proper sanitization.
Who is affected by CVE-2025-27824?
CVE-2025-27824 affects users of Backdrop CMS with versions prior to 1.x-1.1.1 that have the Link iframe formatter module installed.
Can an attacker exploit CVE-2025-27824 easily?
An attacker must have permission to create content containing an iframe, making exploitation dependent on user permissions.