Inpsyde
Inpsyde is a WordPress plugin development firm whose vulnerability footprint centers on security and backup-related plugins such as BackWPup, reflecting the vendor's focus on the WordPress ecosystem. Its disclosures recur around path-traversal and directory-access weaknesses characteristic of file-handling and upload-management code, alongside cross-site scripting issues typical of web-application plugins. Live severity, exploitation, and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Inpsyde over time
Products(2 total)
Top CVEs
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7164HIGH The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's dat | Apr 8, 2024 | 7.5 | 33 | NO | YES |
CVE-2023-5504HIGH The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated attackers to store | Jan 11, 2024 | 8.7 | 26 | NO | NO |
CVE-2023-5505MEDIUM The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attacke | Aug 17, 2024 | 6.8 | 22 | NO | NO |
CVE-2021-25071MEDIUM The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | Mar 28, 2022 | 6.1 | 21 | NO | NO |
CVE-2017-2551HIGH Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download. | Sep 28, 2017 | 7.5 | 19 | NO | NO |
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improp | Feb 26, 2024 | 2.7 | 13 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (6 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Inpsyde.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Inpsyde — matched by CVE ID, not by vendor name.