Urbackup is a focused backup and disaster-recovery product that, despite a narrow portfolio, operates in data-critical infrastructure where authentication and input handling matter to defenders. The vendor's observed vulnerabilities cluster around improper input validation, cross-site scripting, null-pointer dereferences, and observable discrepancies—patterns typical of web-facing backup appliances where parser robustness and access control are structural concerns. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Urbackup over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20013HIGH In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThread::ProcessPacket metadata_id! | Jun 18, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-20014HIGH In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThread::GetFileHashAndMetadata NUL | Jun 7, 2019 | 7.5 | 24 | NO | NO |
CVE-2017-16950MEDIUM Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | Dec 17, 2017 | 6.1 | 21 | NO | NO |
CVE-2023-47102MEDIUM UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid. | Nov 7, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Urbackup.
Media articles that mention a CVE ID that affects a product developed by Urbackup — matched by CVE ID, not by vendor name.