Cobiansoft develops backup and file-synchronization utilities, with a vulnerability profile centered on buffer overflow, OS command injection, and search-path issues affecting products such as Cobian Backup and Reflector. These weakness classes reflect input-handling and command-execution patterns typical of system-level backup and synchronization tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cobiansoft over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-50923HIGH Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquo | Jan 13, 2026 | 7.8 | 24 | NO | NO |
CVE-2017-11318HIGH Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed. In addition, the attacker can execute system comma | Jul 17, 2017 | 8.1 | 23 | NO | NO |
CVE-2022-50689MEDIUM Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a | Dec 22, 2025 | 5.5 | 20 | NO | NO |
CVE-2022-50687MEDIUM Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generat | Dec 22, 2025 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cobiansoft.
Media articles that mention a CVE ID that affects a product developed by Cobiansoft — matched by CVE ID, not by vendor name.