Backupbolt maintains a focused backup and data-protection product with a narrow but specialized role in enterprise environments. The observed vulnerability pattern centers on cross-site scripting in web-facing interfaces, a common input-handling issue in management and control-panel software. Live severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Backupbolt over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup_batch() | Oct 3, 2025 | 3.8 | 17 | NO | NO |
CVE-2025-49040MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery.This issue affects Backup Bolt: from n/a through <= 1.5.0. | Aug 27, 2025 | 4.3 | 17 | NO | NO |
CVE-2023-7236MEDIUM The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers | Mar 18, 2024 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Backupbolt.
Media articles that mention a CVE ID that affects a product developed by Backupbolt — matched by CVE ID, not by vendor name.