Appcheap
Appcheap APP Builder: vulnerabilities and CVEs
Appcheap APP Builder has 8 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months3
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13723 | Medium (6.5) | 0.48% | — | Jul 29, 2026 | A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink… |
| CVE-2026-7638 | Medium (5.3) | 0.51% | — | May 2, 2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization… |
| CVE-2026-2375 | Medium (6.5) | 0.28% | — | Mar 21, 2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.10. This is due to the `verify_role()` function in… |
| CVE-2025-49989 | Medium (5.3) | 0.31% | — | Jun 20, 2025 | Missing Authorization vulnerability in App Cheap App Builder app-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects App Builder: from n/a through <= 5.5.6. |
| CVE-2024-9302 | Critical (9.8) | 0.61% | — | Oct 25, 2024 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the… |
| CVE-2024-7651 | High (7.5) | 0.45% | — | Aug 21, 2024 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injection via the ‘app-builder-search’ parameter in all versions up to, and including, 4.2.6 due to… |
| CVE-2024-32565 | Medium (6.5) | 0.31% | — | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appcheap.Io App Builder allows Stored XSS.This issue affects App Builder: from n/a through 3.8.8. |
| CVE-2024-31282 | Medium (6.1) | 0.33% | — | Apr 10, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7. |