Backintime Project maintains a focused backup and file-versioning utility where disclosed vulnerabilities center on race conditions in concurrent file operations and OS command-injection flaws in shell-command handling. These weakness patterns reflect the product's role as a system-level backup tool with direct filesystem and command-execution responsibilities. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Backintime Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7572HIGH The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subj | Apr 6, 2017 | 8.1 | 26 | NO | NO |
CVE-2017-16667HIGH backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being ex | Nov 8, 2017 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Backintime Project.
Media articles that mention a CVE ID that affects a product developed by Backintime Project — matched by CVE ID, not by vendor name.