CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Deliciousbrains 1Database Backup Jun 17, 2026 Jun 8, 2022 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. T...Show more |
1Deliciousbrains 1Database Backup Jun 17, 2026 Feb 21, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue |
1Deliciousbrains 1Database Backup Jun 17, 2026 Jun 1, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue. |