VYPR

backdropcms.org

by Backdropcms.org

CVEs (1)

  • CVE-2026-107914HigOct 9, 2026
    risk 0.44cvss 7.8epss —

    Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize,…