> The database it is pulling from can be and has been written to by third parties, and will show up on the live website.
Not enough detail to say for sure; could be SQL injection, could be credentials exposed in the frontend.
Not enough detail to say for sure; could be SQL injection, could be credentials exposed in the frontend.