CVE Database
/

CVE-2025-71310

Back to search

CVE-2025-71310

Published: May 26, 2026

Modified: May 26, 2026

PUBLISHED

Description

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration.

VendorProductVersions

BackdropCMS

GDPR cookies module for Backdrop CMS

affected
0 - < 1.x-1.3.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now