CVE-2025-27823: Backdropcms Mail Disguise
Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdrop CMS. It enables a website to obfuscate email addresses, and should prevent spambots from collecting them. The module doesn't sufficiently validate the data attribute value on links, potentially leading to a Cross Site Scripting (XSS) vulnerability. This is mitigated by the fact an attacker must be able to insert link (<a>) HTML elements containing data attributes into the page.
Affected products
- Backdropcms Mail Disguise: before 1.x-1.0.5 (fixed in 1.x-1.0.5)
Published 2025-03-07. Last modified 2026-06-17.