Smartbear
Products
11- 5 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
23| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12835 | Cri | 0.65 | 9.8 | 0.13 | May 20, 2020 | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a… | ||
| CVE-2023-22889 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users. | ||
| CVE-2018-20580 | Hig | 0.61 | 8.8 | 0.10 | May 3, 2019 | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | ||
| CVE-2020-26118 | Hig | 0.58 | 8.8 | 0.04 | Jan 11, 2021 | In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly… | ||
| CVE-2019-17495 | Cri | 0.57 | 9.8 | 0.06 | Oct 10, 2019 | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product… | ||
| CVE-2023-22891 | Hig | 0.53 | 8.1 | 0.01 | Mar 8, 2023 | There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts. | ||
| CVE-2024-7565 | Hig | 0.51 | 7.8 | 0.01 | Nov 22, 2024 | SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the… | ||
| CVE-2019-12180 | Hig | 0.51 | 7.8 | 0.05 | Feb 5, 2020 | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim… | ||
| CVE-2017-16670 | Hig | 0.51 | 7.8 | 0.02 | Feb 19, 2018 | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file. | ||
| CVE-2023-22892 | Hig | 0.49 | 7.5 | 0.01 | Mar 8, 2023 | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances. | ||
| CVE-2023-22890 | Hig | 0.49 | 7.5 | 0.01 | Mar 8, 2023 | SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition. | ||
| CVE-2025-29157 | Med | 0.42 | 6.5 | 0.01 | Sep 25, 2025 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version | ||
| CVE-2025-29155 | Med | 0.42 | 6.5 | 0.00 | Sep 25, 2025 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint | ||
| CVE-2025-29156 | Med | 0.40 | 6.1 | 0.00 | Sep 25, 2025 | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet | ||
| CVE-2021-46708 | Med | 0.40 | 6.1 | 0.01 | Mar 11, 2022 | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and… | ||
| CVE-2021-41657 | Med | 0.40 | 6.1 | 0.01 | Mar 10, 2022 | SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack. | ||
| CVE-2016-1000229 | Med | 0.40 | 6.1 | 0.04 | Dec 20, 2019 | swagger-ui has XSS in key names | ||
| CVE-2016-5682 | Med | 0.40 | 6.1 | 0.01 | Apr 10, 2017 | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. | ||
| CVE-2024-22207 | Med | 0.28 | 5.3 | 0.02 | Jan 15, 2024 | fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is… | ||
| CVE-2021-21364 | Med | 0.27 | 5.3 | 0.00 | Mar 11, 2021 | swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the… |
- risk 0.65cvss 9.8epss 0.13
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a…
- risk 0.64cvss 9.8epss 0.01
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
- risk 0.61cvss 8.8epss 0.10
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
- risk 0.58cvss 8.8epss 0.04
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly…
- risk 0.57cvss 9.8epss 0.06
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product…
- risk 0.53cvss 8.1epss 0.01
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.
- risk 0.51cvss 7.8epss 0.01
SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the…
- risk 0.51cvss 7.8epss 0.05
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim…
- risk 0.51cvss 7.8epss 0.02
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
- risk 0.49cvss 7.5epss 0.01
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
- risk 0.49cvss 7.5epss 0.01
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition.
- risk 0.42cvss 6.5epss 0.01
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version
- risk 0.42cvss 6.5epss 0.00
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet
- risk 0.40cvss 6.1epss 0.01
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and…
- risk 0.40cvss 6.1epss 0.01
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.
- risk 0.40cvss 6.1epss 0.04
swagger-ui has XSS in key names
- risk 0.40cvss 6.1epss 0.01
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
- risk 0.28cvss 5.3epss 0.02
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is…
- risk 0.27cvss 5.3epss 0.00
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the…