Buttercms is a headless CMS platform with a narrow vulnerability surface centered on its core product. The durable signal is a recurring weakness class around unrestricted file upload, reflecting the common implementation challenge of validating user-supplied content in web-based content-management systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Buttercms over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27260CRITICAL An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file. | Apr 12, 2022 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Buttercms.
Media articles that mention a CVE ID that affects a product developed by Buttercms — matched by CVE ID, not by vendor name.