BackupBuddy versions 8.5.8.0 - 8.7.4.1 are vulnerable to a local file inclusion vulnerability via the ‘download’ and ‘local-destination-id’ parameters.
View the template here CVE-2022-31474.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2022-31474