The GDPR cookies module for Backdrop CMS (before
1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://backdropcms.org/security/sa-contrib-2025-013 |
Configurations
No configuration.
History
26 May 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-26 02:16
Updated : 2026-05-26 19:57
NVD link : CVE-2025-71310
Mitre link : CVE-2025-71310
CVE.ORG link : CVE-2025-71310
JSON object : View
Products Affected
No product.
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
