Date: 
Wednesday, Sep 23rd, 2026
Advisory ID: 
BACKDROP-SA-CORE-2026-005
Security risk: 
Moderately Critical
Vulnerability: 
Third Party Libraries
Versions affected: 
  • Backdrop Core 1.35.x versions prior to 1.35.1

Backdrop versions 1.33 and prior do not receive security coverage. Note that the 1.34.x branch also did not receive this update because of significant CKEditor version discrepancies between 1.34.x and 1.35.x, and CKEditor does not provide security updates to previous versions. As such this update was only applied to 1.35.1.

Description: 

The Backdrop project uses the CKEditor library for rich-text editing. CKEditor has released a security update that impacts Backdrop CMS.

Vulnerabilities are possible if Backdrop is configured to use CKEditor for rich-text editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target other people with access to the rich-text CKEditor, including site admins with privileged access.

For more information, see CKEditor's security advisory:

Instructions for contributed modules

Some contributed projects may use additional CKEditor plugins that are not packaged in Backdrop core. People should review their own sites if they use one of these projects. CKEditor has also released another CVE that does not affect Backdrop, but may affect custom plugins or other use cases:

Solution: 

Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.35.1 release page. See the update instructions.

Fixed By: 
Coordinated By: 

Security email list

Backdrop maintains a security mailing list. Whenever a security release comes out, an email will be sent to everyone subscribed to that list, announcing the new release. Please follow the steps below to join the Security email list.

  1. Log in to backdropcms.org
  2. Edit your profile
  3. Switch to the "Subscriptions" tab
  4. Check the box labeled "Security updates"
  5. Save the form