Ahsay develops a focused cloud backup and recovery platform that serves as a critical data-protection layer across enterprise and mid-market environments, and its vulnerability profile centers on a single product line with a marked tendency toward public exploit availability. The recurring weakness classes—XML external entity injection, unrestricted file uploads, path traversal, argument injection, and cross-site scripting—reflect the input-handling and file-management demands of a web-facing backup appliance and are characteristic of application-layer security gaps that attract tooling and proof-of-concept development. Defenders should treat this vendor's advisories as requiring prompt patching, particularly for internet-reachable deployments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ahsay over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10267HIGH An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can inse | Jul 26, 2019 | 8.8 | 83 | NO | YES |
CVE-2019-10266HIGH An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the con | Jul 26, 2019 | 7.5 | 40 | NO | YES |
CVE-2022-37027HIGH Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject | Sep 21, 2022 | 7.2 | 35 | NO | NO |
CVE-2019-10265HIGH An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to change the directory in the JavaSc | Jul 26, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-10264HIGH An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen has an Import Users option. This | Jul 26, 2019 | 7.2 | 23 | NO | NO |
CVE-2020-5846HIGH An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in t | Jan 6, 2020 | 8.8 | 22 | NO | NO |
CVE-2019-10263MEDIUM An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrie | Jul 26, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ahsay.
Media articles that mention a CVE ID that affects a product developed by Ahsay — matched by CVE ID, not by vendor name.