Matthewdeaves maintains the Willow CMS product, a content-management system where the observed vulnerability pattern centers on application-layer security issues including improper access control, code injection, cross-site scripting, and unrestricted file uploads. These weakness classes reflect common risks in web-facing administrative platforms where input handling and authorization boundaries are critical; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matthewdeaves over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12331HIGH A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unrestricted upload. Remote exploi | Oct 27, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-12330MEDIUM A security flaw has been discovered in Willow CMS up to 1.4.0. This issue affects some unknown processing of the file /admin/articles/add of the component Add Post Page. The manipu | Oct 27, 2025 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matthewdeaves.
Media articles that mention a CVE ID that affects a product developed by Matthewdeaves — matched by CVE ID, not by vendor name.