CVE-2026-45430: Backdrop CMS Contributed Projects Backdrop-Contrib/salesforce

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.

Affected products

Published 2026-05-12. Last modified 2026-06-17.