Link iframe formatter - Moderately critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-003
The Link iframe formatter module doesn't sufficiently sanitize user input before displaying results to the screen.
This vulnerability is mitigated by the fact that an attacker must have the ability to create content containing an iFrame field.
- Link iframe formatter module, 1.x versions prior to 1.x-1.1.1