216.73.216.6

CVE-2025-71310

· Published 26/05/2026 02:16 · Modified 26/05/2026 19:57

Labels: CVE-2025-71310 2026-05-26CVE-2025-71310CWE-80[email protected]

Essential information

Published
26/05/2026 02:16
Modified
26/05/2026 19:57
Author
Creator
CVSS
1.8 LOW (v3) 1.8 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
backdrop / backdrop cms cpe:2.3:a:backdrop:backdrop_cms:<1.x-1.3.5:*:*:*:*:*:*:*

References