Vinchin is a backup-and-recovery vendor whose vulnerability footprint concentrates in its core backup product, where disclosures skew strongly toward critical-severity outcomes and have an elevated tendency to acquire public exploit code. The recurring weakness classes—command injection, hard-coded credentials, and code injection—reflect the code-execution risk inherent to administrative backup software that often runs with high privilege and processes untrusted data. Defenders should treat this vendor's advisories as high-priority for any instances managing production data; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vinchin over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45498CRITICAL VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability. | Oct 27, 2023 | 9.8 | 51 | NO | YES |
CVE-2023-45499CRITICAL VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials. | Oct 27, 2023 | 9.8 | 46 | NO | YES |
CVE-2024-25228HIGH Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php. | Mar 14, 2024 | 8.8 | 35 | NO | NO |
CVE-2024-22902CRITICAL Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials. | Feb 2, 2024 | 9.8 | 32 | NO | NO |
CVE-2022-35866CRITICAL This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit | Aug 3, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-22903HIGH Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function. | Feb 2, 2024 | 8.8 | 29 | NO | NO |
CVE-2024-22900HIGH Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function. | Feb 2, 2024 | 8.8 | 27 | NO | NO |
CVE-2024-22901CRITICAL Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials. | Feb 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-22899HIGH Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function. | Feb 2, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vinchin.
Media articles that mention a CVE ID that affects a product developed by Vinchin — matched by CVE ID, not by vendor name.