Stacksmarket's vulnerability footprint centers on its Stacks Mobile App Builder, a low-code development platform, with a durable signal rooted in authentication and information-disclosure weaknesses including authentication bypass via alternate channels, missing authentication for critical functions, and exposure of sensitive system information. These patterns reflect the attack surface inherent to web-accessible development and deployment tools where improper access controls can lead to unauthorized manipulation of application logic and data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stacksmarket over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50477CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects | Oct 28, 2024 | 9.8 | 46 | NO | YES |
CVE-2024-50527CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue aff | Nov 4, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-50528HIGH Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sens | Nov 4, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stacksmarket.
Media articles that mention a CVE ID that affects a product developed by Stacksmarket — matched by CVE ID, not by vendor name.