Date: 
Monday, Aug 25th, 2025
Advisory ID: 
BACKDROP-SA-CONTRIB-2025-015
Security risk: 
Less Critical
Vulnerability: 
Third Party Libraries
Versions affected: 
  • All module filter versions prior to 1.x-2.2.3
Description: 

Module filter module included an older version of the jQuery BBQ library, which contained a security vulnerability.

The risk may be mitigated by users needing to have access to this module that would be restricted to the administrator role.

 

Note: Backdrop security releases are usually made on Wednesdays. This release was accidentally created out of band.

 

Solution: 

Upgrade your site to use the most recent version of Module filter module. Download available on the Module Filter project page.

Reported By: 
Fixed By: 

Security email list

Backdrop maintains a security mailing list. Whenever a security release comes out, an email will be sent to everyone subscribed to that list, announcing the new release. Please follow the steps below to join the Security email list.

  1. Log in to backdropcms.org
  2. Edit your profile
  3. Switch to the "Subscriptions" tab
  4. Check the box labeled "Security updates"
  5. Save the form