- Backdrop Core 1.x.x versions prior to 1.9.4
CKEditor, a third-party JavaScript library included in Backdrop core, has fixed a cross-site scripting (XSS) vulnerability. The vulnerability stemmed from the fact that it was possible to execute XSS inside CKEditor when using the image2 plugin (which Backdrop core also uses).
Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.9.4 release page. See the update instructions, if needed.
- Marek Lewandowski of the CKEditor team
- Wiktor Walc of the CKEditor team
- Nate Lampton of the Backdrop CMS Security Team
- Geoff St. Pierre of the Backdrop CMS Security Team
- Jen Lampton of the Backdrop CMS Security Team