Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 10.0
CVE-2026-50160EPSS 18%
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated P…
Hoppscotch
2026.5.0+
CRITICAL 9.6
CVE-2026-34931
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfilt…
Hoppscotch
2026.3.0+
CRITICAL 9.3
CVE-2026-34932
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This is…
Hoppscotch
2026.3.0+
MEDIUM 6.1
CVE-2026-34847
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. …
Hoppscotch
2026.3.0+
MEDIUM 5.4
CVE-2026-34848
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow to…
Hoppscotch
2026.3.0+
MEDIUM 6.5
CVE-2026-30825
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authentica…
Hoppscotch
2026.2.1+
HIGH 8.3
CVE-2026-28216
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's perso…
Hoppscotch
2026.2.0+
MEDIUM 6.5
CVE-2026-28217
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection…
Hoppscotch
2026.2.0+
CRITICAL 9.1
CVE-2026-28215
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur…
Hoppscotch
2026.2.0+
MEDIUM 5.4
CVE-2024-27092
Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with …
Hoppscotch
2023.12.6+
HIGH 8.8
CVE-2023-34097
hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the d…
Hoppscotch
2023.4.5+
HIGH 8.0
CVE-2022-0121
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue aff…
Hoppscotch
after 2.1.0