Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Smartbear

24 known vulnerabilities

3
CRITICAL
8
HIGH
11
MEDIUM

Top Products

zephyr enterprise 4 swagger petstore 3 soapui 3 swagger ui 3 readyapi 3 collaborator 2 swagger-codegen 2 swagger-ui 2 swagger-ui-dist 1
22 CVEs
6.5
CVE-2025-29157

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/ca

6.1
CVE-2025-29156

Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted

6.5
CVE-2025-29155

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint

7.8
CVE-2024-7565

SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote

5.3
CVE-2024-22207

fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/s

7.5
CVE-2023-22892

There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploit

8.1
CVE-2023-22891

There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited

7.5
CVE-2023-22890

SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the l

9.8
CVE-2023-22889

SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to re

6.1
CVE-2021-46708

The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the

4.3
CVE-2018-25031

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a

6.1
CVE-2021-41657

SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attack

5.3
CVE-2021-21364

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients

5.3
CVE-2021-21363

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients

8.8
CVE-2020-26118

In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentic

9.8
CVE-2020-12835

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an un

7.8
CVE-2019-12180

An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, th

6.1
CVE-2016-1000229

swagger-ui has XSS in key names

9.8
CVE-2019-17495

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative

8.8
CVE-2018-20580

The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co

7.8
CVE-2017-16670

The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted re

6.1
CVE-2016-5682

Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.

Frequently Asked Questions

How many CVEs affect Smartbear?

Smartbear has 24 CVE records in our database, including 3 critical and 10 high severity vulnerabilities.

What are the most severe Smartbear vulnerabilities?

Smartbear has 3 critical severity (CVSS 9.0+) and 10 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Smartbear vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Smartbear products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Smartbear Vulnerabilities

CyberStrike scans your infrastructure for Smartbear vulnerabilities and provides real-time remediation guidance.

Get Started