Smartbear
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Smartbear product.
RSS Feeds for Smartbear security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Smartbear products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Smartbear Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Smartbear. Smartbear did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 2 | 6.55 |
| 2023 | 4 | 8.23 |
| 2022 | 3 | 5.50 |
| 2021 | 2 | 6.25 |
| 2020 | 1 | 0.00 |
| 2019 | 2 | 0.00 |
It may take a day or so for new Smartbear vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Smartbear Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2024-7565 | Nov 22, 2024 |
SMARTBEAR SoapUI Directory Traversal RCE via unpackageAllSMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the unpackageAll function. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-19060. |
|
| CVE-2024-22207 | Jan 15, 2024 |
fastify-swagger-ui Directory Exposure via default config (<2.1.0)fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the `baseDir` option can also work around this vulnerability. |
|
| CVE-2023-22889 | Mar 08, 2023 |
SmartBear Zephyr Enterprise <7.15.0 RCE via report generation mishandleSmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users. |
|
| CVE-2023-22892 | Mar 08, 2023 |
Info disclosure in SmartBear Zephyr Enterprise <=7.15.0 (unauthenticated read)There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances. |
|
| CVE-2023-22890 | Mar 08, 2023 |
Zephyr Enterprise 7.15.0 DDoS via Large File UploadSmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition. |
|
| CVE-2023-22891 | Mar 08, 2023 |
Privilege Escalation in SmartBear Zephyr Enterprise <7.15 via Password ResetThere exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts. |
|
| CVE-2021-46708 | Mar 11, 2022 |
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victimThe swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. |
|
| CVE-2018-25031 | Mar 11, 2022 |
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacksSwagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others. |
|
| CVE-2021-41657 | Mar 10, 2022 |
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which wouldSmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack. |
|
| CVE-2021-21363 | Mar 11, 2021 |
swagger-codegen is an open-source projectswagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. This vulnerability is local privilege escalation because the contents of the `outputFolder` can be appended to by an attacker. As such, code written to this directory, when executed can be attacker controlled. For more details refer to the referenced GitHub Security Advisory. This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21364. |
|
| CVE-2021-21364 | Mar 11, 2021 |
swagger-codegen is an open-source projectswagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between all local users. When files/directories are created, the default `umask` settings for the process are respected. As a result, by default, most processes/apis will create files/directories with the permissions `-rw-r--r--` and `drwxr-xr-x` respectively, unless an API that explicitly sets safe file permissions is used. Because this vulnerability impacts generated code, the generated code will remain vulnerable until fixed manually! This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21363. |
|
| CVE-2019-12180 | Feb 05, 2020 |
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious Project. The same issue is present in the "Save Script" function, which is executed automatically when saving a project. |
|
| CVE-2019-17495 | Oct 10, 2019 |
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method. |
|
| CVE-2018-20580 | May 03, 2019 |
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. |
|