VendorsBaculabacula-weball versions
Vulnerabilities

Bacula Bacula-Web 5.0.3 Alpha

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-15367
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
Published 2018-03-07 · Modified
9.81 PoCEPSS 0.231
CVE-2025-45346
SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.
Published 2025-07-29 · Analyzed
8.1EPSS 0.007
CVE-2014-8295
SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter.
Published 2014-10-15 · Modified
7.51 PoCEPSS 0.023