CVE-2025-27825: Backdropcms Bootstrap 5 Lite Theme

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.

Affected products

  • Backdropcms Bootstrap 5 Lite Theme: before 1.x-1.0.3 (fixed in 1.x-1.0.3)

Published 2025-03-07. Last modified 2026-06-17.