AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-14770

MEDIUM · CVSS 6.1 EPSS 0.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-08 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-14770
Severity
MEDIUM
CVSS
6.1
EPSS
0.79%
Java

Original NVD Description

In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (This issue is mitigated by the attacker needing permissions to create administrative menu links, such as by creating a content type or layout. Such permissions are usually restricted to trusted or administrative users.)