Executive brief
Backdrop CMS Host Header Injection vulnerability
Affected products
- Packagist backdrop/backdrop
Junglewise Threat Intelligence
CVE-2025-63828 · Severity: medium · CVSS 4 · Published 2025-11-18
Technologies: backdrop/backdrop (Packagist). Vendors: Packagist.
Backdrop CMS Host Header Injection vulnerability