CVE-2024-41709: Backdropcms Backdrop
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
Affected products
- Backdropcms Backdrop: from 1.27.0, before 1.27.3 (fixed in 1.27.3); from 1.28.0, before 1.28.2 (fixed in 1.28.2)
Published 2024-07-22. Last modified 2026-06-17.