Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bacula

First CVE: Sep 20, 2005Active for: 21 yearsTotal CVEs: 7

Bacula is a modestly represented backup and recovery platform whose vulnerability footprint, despite limited product breadth, reflects the security exposure inherent in systems that handle sensitive data in transit and at rest. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, with the recurring exposure centered on SQL injection, cleartext transmission of credentials and backup content, and link-following issues that characterize file-handling and database-driven backup software. Defenders should prioritize patching of internet-exposed Bacula directors and storage daemons, and audit backup workflows for credential exposure; live severity and exploitation details are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bacula over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2005
20 years ago
Most Recent CVE
Jul 29, 2025
360 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-15367CRITICAL
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escala
Mar 7, 20189.856NOYES
CVE-2014-8295HIGH
SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter.
Oct 15, 20147.528NOYES
CVE-2025-45346HIGH
SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.
Jul 29, 20258.126NONO
CVE-2008-5373MEDIUM
mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue
Dec 8, 20086.922NONO
CVE-2012-4430MEDIUM
The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump informat
Oct 10, 20124.017NONO
CVE-2007-5626MEDIUM
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line,
Oct 23, 20075.516NONO
CVE-2005-2995LOW
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available
Sep 20, 20053.613NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
43%
29%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (14.3%)
Network2 (28.6%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (28.6%)
High1 (14.3%)
Unknown4 (57.1%)
User Interaction
None3 (42.9%)
Unknown4 (57.1%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None2 (28.6%)
Unknown4 (57.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bacula.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bacula — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bacula's Products

View all 2 CNAs →

Top CWEs