Smartbear
24 known vulnerabilities
Top Products
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/ca
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/s
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploit
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the l
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to re
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attack
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentic
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an un
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, th
swagger-ui has XSS in key names
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted re
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
Frequently Asked Questions
How many CVEs affect Smartbear?
Smartbear has 24 CVE records in our database, including 3 critical and 10 high severity vulnerabilities.
What are the most severe Smartbear vulnerabilities?
Smartbear has 3 critical severity (CVSS 9.0+) and 10 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Smartbear vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Smartbear products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Smartbear Vulnerabilities
CyberStrike scans your infrastructure for Smartbear vulnerabilities and provides real-time remediation guidance.
Get Started