CVE-2026-45430: Backdrop CMS Contributed Projects Backdrop-Contrib/salesforce
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.
Affected products
- Backdrop CMS Contributed Projects Backdrop-Contrib/salesforce: before 1.x-1.0.1 (fixed in 1.x-1.0.1)
Published 2026-05-12. Last modified 2026-06-17.