Skip to main content

Vendor archive

smartbear CVEs

Beta · best-effort

23 CVEs tagged to vendor smartbear4 Critical, 8 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2025-29157

Published Sep 25, 2025

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-29156

Published Sep 25, 2025

Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7565

Published Nov 22, 2024

SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22207

Published Jan 15, 2024

fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22892

Published Mar 8, 2023

There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Ze…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22891

Published Mar 8, 2023

There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22890

Published Mar 8, 2023

SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22889

Published Mar 8, 2023

SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-46708

Published Mar 11, 2022

The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web sit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-25031

Published Mar 11, 2022

Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41657

Published Mar 10, 2022

SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21364

Published Mar 11, 2021

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your Op…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21363

Published Mar 11, 2021

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your Op…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26118

Published Jan 11, 2021

In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12835

Published May 20, 2020

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serial…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12180

Published Feb 5, 2020

An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20580

Published May 3, 2019

The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16670

Published Feb 19, 2018

The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1202

Published Jan 25, 2014

The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1