SMARTBEAR records
23 published records for vendor smartbear.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 39.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-1021 Improper Restriction of Rendered UI Layers or Frames2
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2020-12835No exploit | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.smartbear · readyapi · CWE-502 | Critical9.8 | — | 13.0% | May 20, 2020 |
41Plan | CVE-2019-17495Proof of concept | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPOsmartbear · swagger ui · CWE-352 | Critical9.8 | — | 5.7% | Oct 10, 2019 |
39Monitor | CVE-2014-1202Proof of concept | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameviware · soapui · CWE-94 | Critical9.3 | — | 7.7% | Jan 24, 2014 |
39Monitor | CVE-2023-22889No exploit | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.smartbear · zephyr enterprise · CWE-94 | Critical9.8 | — | 1.3% | Mar 8, 2023 |
38Monitor | CVE-2018-20580Proof of concept | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted reqsmartbear · readyapi · CWE-20 | High8.8 | — | 9.8% | May 3, 2019 |
36Monitor | CVE-2020-26118No exploit | In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialismartbear · collaborator · CWE-502 | High8.8 | — | 3.8% | Jan 11, 2021 |
32Monitor | CVE-2019-12180Proof of concept | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.smartbear · readyapi | High7.8 | — | 4.8% | Feb 5, 2020 |
32Monitor | CVE-2023-22891No exploit | There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users smartbear · zephyr enterprise · CWE-863 | High8.1 | — | 0.5% | Mar 8, 2023 |
31Monitor | CVE-2017-16670No exploit | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in asmartbear · soapui · CWE-94 | High7.8 | — | 1.6% | Feb 19, 2018 |
31Monitor | CVE-2024-7565No exploit | SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerabilitysmartbear · soapui · CWE-22 | High7.8 | — | 1.0% | Nov 22, 2024 |
30Monitor | CVE-2018-25031Proof of concept | Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.smartbear · swagger ui · CWE-20 | Medium4.3 | — | 42.3% | Mar 11, 2022 |
30Monitor | CVE-2023-22890No exploit | SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, casmartbear · zephyr enterprise · CWE-434 | High7.5 | — | 0.6% | Mar 8, 2023 |
30Monitor | CVE-2023-22892No exploit | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticatesmartbear · zephyr enterprise · CWE-668 | High7.5 | — | 0.6% | Mar 8, 2023 |
28Monitor | CVE-2021-21363No exploit | Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directorysmartbear · swagger-codegen · CWE-378 | High7.0 | — | 0.4% | Mar 10, 2021 |
26Monitor | CVE-2025-29157No exploit | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retursmartbear · swagger petstore · CWE-77 | Medium6.5 | — | 0.5% | Sep 25, 2025 |
26Monitor | CVE-2025-29155No exploit | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpointsmartbear · swagger petstore · CWE-77 | Medium6.5 | — | 0.4% | Sep 25, 2025 |
25Monitor | CVE-2016-1000229Proof of concept | swagger-ui has XSS in key namessmartbear · swagger-ui · CWE-79 | Medium6.1 | — | 4.0% | Dec 20, 2019 |
24Monitor | CVE-2021-46708No exploit | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.smartbear · swagger-ui-dist · CWE-1021 | Medium6.1 | — | 1.5% | Mar 11, 2022 |
24Monitor | CVE-2016-5682No exploit | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.smartbear · swagger-ui · CWE-79 | Medium6.1 | — | 1.0% | Apr 9, 2017 |
24Monitor | CVE-2021-41657No exploit | SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clicsmartbear · collaborator · CWE-1021 | Medium6.1 | — | 0.8% | Mar 10, 2022 |
24Monitor | CVE-2025-29156No exploit | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/vsmartbear · swagger petstore · CWE-79 | Medium6.1 | — | 0.4% | Sep 25, 2025 |
22Monitor | CVE-2024-22207Proof of concept | Default swagger-ui configuration exposes all files in the modulesmartbear · swagger ui · CWE-1188 | Medium5.3 | — | 2.3% | Jan 15, 2024 |
22Monitor | CVE-2021-21364No exploit | Generated Code Contains Local Information Disclosure Vulnerabilitysmartbear · swagger-codegen · CWE-200 | Medium5.5 | — | 0.3% | Mar 10, 2021 |
- CVE-2020-1283543Plan
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.
CriticalCVSS 9.8No exploitEPSS 13%smartbear · readyapiMay 20, 2020
- CVE-2019-1749541Plan
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO
CriticalCVSS 9.8Proof of conceptEPSS 6%smartbear · swagger uiOct 10, 2019
- CVE-2014-120239Monitor
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request param
CriticalCVSS 9.3Proof of conceptEPSS 8%eviware · soapuiJan 24, 2014
- CVE-2023-2288939Monitor
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.
CriticalCVSS 9.8No exploitEPSS 1%smartbear · zephyr enterpriseMar 8, 2023
- CVE-2018-2058038Monitor
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted req
HighCVSS 8.8Proof of conceptEPSS 10%smartbear · readyapiMay 3, 2019
- CVE-2020-2611836Monitor
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deseriali
HighCVSS 8.8No exploitEPSS 4%smartbear · collaboratorJan 11, 2021
- CVE-2019-1218032Monitor
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.
HighCVSS 7.8Proof of conceptEPSS 5%smartbear · readyapiFeb 5, 2020
- CVE-2023-2289132Monitor
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users
HighCVSS 8.1No exploitEPSS 1%smartbear · zephyr enterpriseMar 8, 2023
- CVE-2017-1667031Monitor
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a
HighCVSS 7.8No exploitEPSS 2%smartbear · soapuiFeb 19, 2018
- CVE-2024-756531Monitor
SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 1%smartbear · soapuiNov 22, 2024
- CVE-2018-2503130Monitor
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.
MediumCVSS 4.3Proof of conceptEPSS 42%smartbear · swagger uiMar 11, 2022
- CVE-2023-2289030Monitor
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, ca
HighCVSS 7.5No exploitEPSS 1%smartbear · zephyr enterpriseMar 8, 2023
- CVE-2023-2289230Monitor
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticate
HighCVSS 7.5No exploitEPSS 1%smartbear · zephyr enterpriseMar 8, 2023
- CVE-2021-2136328Monitor
Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory
HighCVSS 7.0No exploitEPSS 0%smartbear · swagger-codegenMar 10, 2021
- CVE-2025-2915726Monitor
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retur
MediumCVSS 6.5No exploitEPSS 1%smartbear · swagger petstoreSep 25, 2025
- CVE-2025-2915526Monitor
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
MediumCVSS 6.5No exploitEPSS 0%smartbear · swagger petstoreSep 25, 2025
- CVE-2016-100022925Monitor
swagger-ui has XSS in key names
MediumCVSS 6.1Proof of conceptEPSS 4%smartbear · swagger-uiDec 20, 2019
- CVE-2021-4670824Monitor
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.
MediumCVSS 6.1No exploitEPSS 1%smartbear · swagger-ui-distMar 11, 2022
- CVE-2016-568224Monitor
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
MediumCVSS 6.1No exploitEPSS 1%smartbear · swagger-uiApr 9, 2017
- CVE-2021-4165724Monitor
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clic
MediumCVSS 6.1No exploitEPSS 1%smartbear · collaboratorMar 10, 2022
- CVE-2025-2915624Monitor
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v
MediumCVSS 6.1No exploitEPSS 0%smartbear · swagger petstoreSep 25, 2025
- CVE-2024-2220722Monitor
Default swagger-ui configuration exposes all files in the module
MediumCVSS 5.3Proof of conceptEPSS 2%smartbear · swagger uiJan 15, 2024
- CVE-2021-2136422Monitor
Generated Code Contains Local Information Disclosure Vulnerability
MediumCVSS 5.5No exploitEPSS 0%smartbear · swagger-codegenMar 10, 2021