CVE-2025-27826: Backdropcms Bootstrap Lite Theme

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanitize certain class names.

Affected products

  • Backdropcms Bootstrap Lite Theme: before 1.x-1.4.5 (fixed in 1.x-1.4.5)

Published 2025-03-07. Last modified 2026-06-17.