CVE-2024-54123

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/11/2024
Last modified:
26/01/2026

Description

Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:* 1.28.4 (excluding)
cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:* 1.29.0 (including) 1.29.2 (excluding)


References to Advisories, Solutions, and Tools