- Bootstrap 5 Lite module, 1.x versions prior to 1.x-1.0.3.
The Bootstrap 5 Lite Backdrop CMS theme doesn't sufficiently sanitize certain class names.
A CVE has been requested, and this page will be updated as soon as an official number has been issued.
Upgrade your site to use the most recent version of Bootstrap 5 Lite. Download available on the Bootstrap 5 Lite 1.0.3 release page.
- Kevin van Hulst
- Jen Lampton of the Backdrop CMS Security Team