Buildapp's vulnerability profile centers on its Build App Online platform, a web-based application development tool where the observed weakness classes cluster around authentication, access control, and input handling—including CSRF, improper authentication, PHP remote file inclusion, improper privilege management, and inclusion of untrusted functionality. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Buildapp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-49649CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online build-app-online allows PHP Loc | Jan 7, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-7264CRITICAL The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possi | Jun 11, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-51478CRITICAL Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19. | Apr 25, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-51479HIGH Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19. | May 17, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-53751HIGH Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online build-app-online allows Cross Site Request Forgery.This issue affects Build App Online: from n/a thro | Dec 2, 2024 | 8.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Buildapp.
Media articles that mention a CVE ID that affects a product developed by Buildapp — matched by CVE ID, not by vendor name.