← Back

Bacula Web

bacula-web

Vendor: Bacula • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bacula
1Bacula Web
Aug 6, 2025
Jul 29, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.
1Bacula
1Bacula Web
Nov 21, 2024
Mar 7, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
1Bacula
1Bacula Web
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter.