Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Buildbot

First CVE: Aug 25, 2009Active for: 17 yearsTotal CVEs: 4

Buildbot is a continuous-integration automation platform whose vulnerability exposure centers on web-interface attack vectors, with the recurring weakness classes spanning cross-site scripting, authentication bypass, and CRLF injection—issues typical of application-layer input handling in systems exposed to untrusted build environments. The vendor's footprint is narrow and specialized, making it a targeted concern primarily for organizations operating self-hosted CI/CD infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Buildbot over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2009
16 years ago
Most Recent CVE
May 23, 2019
2,619 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12300CRITICAL
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to r
May 23, 20199.832NONO
CVE-2019-7313MEDIUM
www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in th
Feb 3, 20196.120NONO
CVE-2009-2967MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, differ
Aug 26, 20094.317NONO
CVE-2009-2959MEDIUM
Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary w
Aug 25, 20094.314NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
75%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network2 (50.0%)
Unknown2 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (50.0%)
High0 (0.0%)
Unknown2 (50.0%)
User Interaction
None1 (25.0%)
Unknown2 (50.0%)
Required1 (25.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (50.0%)
Unknown2 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Buildbot.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Buildbot — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Buildbot's Products

View all 1 CNAs →

Top CWEs