CVE-2025-25063 - CVE House
Back to Database
Status published Medium CVE-2025-25063

An XSS issue was discovered in Backdrop CMS 1.28.x before...

Vulnerability Description

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and executable scripting, and using a crafted SVG, it is possible to execute scripting in the browser when an SVG image is viewed. This issue is mitigated by the attacker needing to be able to upload SVG images, and that Backdrop embeds all uploaded SVG images within <img> tags, which prevents scripting from executing. The SVG must be viewed directly by its URL in order to run any embedded scripting.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-25063

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

backdropcms

View all reports →

Affected Software

backdrop
Vulnerable Versions:
1.28.0, 1.29.0

Timeline

Official Publish: February 3rd, 2025
Last Modified: February 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)