Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Backupbliss

First CVE: Nov 19, 2021Active for: 5 yearsTotal CVEs: 12
56.1
VTI Score
TOP TARGET

Backupbliss develops backup and migration software whose vulnerabilities skew toward serious outcomes, with a meaningful share reaching critical severity and a notable tendency toward public exploit availability. The recurring exposure centers on its Backup Migration and Clone products and clusters around access-control weaknesses—including missing authorization checks, cross-site request forgery, and improper file/directory permissions—that reflect the sensitive nature of backup data and the administrative interfaces through which backups are managed and restored. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Backupbliss over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2021
4 years ago
Most Recent CVE
Nov 1, 2024
630 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-6553CRITICAL
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to
Dec 15, 20239.893NOYES
CVE-2023-7002HIGH
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows auth
Dec 23, 20237.244NONO
CVE-2023-6750HIGH
The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.
Jan 8, 20247.537NOYES
CVE-2023-6266HIGH
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading
Jan 11, 20247.532NOYES
CVE-2023-6972CRITICAL
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifes
Dec 23, 20239.831NONO
CVE-2023-6971CRITICAL
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenti
Dec 23, 20239.831NONO
CVE-2024-43298HIGH
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
Nov 1, 20248.823NONO
CVE-2024-43297HIGH
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
Nov 1, 20248.823NONO
CVE-2023-6271HIGH
The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to
Jan 1, 20247.522NONO
CVE-2021-36884MEDIUM
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.
Nov 19, 20215.420NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
25%
50%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low4 (33.3%)
High1 (8.3%)
None7 (58.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 98th percentile
Nuclei
3 CVEs
25.0% of CVEs· 97th percentile
ExploitDB
1 CVE
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Backupbliss.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Backupbliss — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Backupbliss's Products

View all 3 CNAs →

Top CWEs