Yes, THAT is an issue. That's something I do not do. For me, I may have a few sites on one server, all my own never another persons sites and all databases are hosted off site.
That's the best way to do it in my opinion. Otherwise, if one site gets hacked then you're SOL. All data would be...