Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hoppscotch CRITICAL 10.0
CVE-2026-50160EPSS 18%

Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated P…

Fix: 2026.5.0+
Fix from $2,300 2026-07-01
Hoppscotch CRITICAL 9.6
CVE-2026-34931

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfilt…

Fix: 2026.3.0+
Fix from $2,300 2026-04-02
Hoppscotch CRITICAL 9.3
CVE-2026-34932

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This is…

Fix: 2026.3.0+
Fix from $2,300 2026-04-02
Hoppscotch MEDIUM 6.1
CVE-2026-34847

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. …

Fix: 2026.3.0+
Fix from $1,600 2026-04-02
Hoppscotch MEDIUM 5.4
CVE-2026-34848

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow to…

Fix: 2026.3.0+
Fix from $1,600 2026-04-02
Hoppscotch MEDIUM 6.5
CVE-2026-30825

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authentica…

Fix: 2026.2.1+
Fix from $1,600 2026-03-07
Hoppscotch HIGH 8.3
CVE-2026-28216

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's perso…

Fix: 2026.2.0+
Fix from $1,950 2026-02-26
Hoppscotch MEDIUM 6.5
CVE-2026-28217

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection…

Fix: 2026.2.0+
Fix from $1,600 2026-02-26
Hoppscotch CRITICAL 9.1
CVE-2026-28215

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur…

Fix: 2026.2.0+
Fix from $2,300 2026-02-26
Hoppscotch MEDIUM 5.4
CVE-2024-27092

Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with …

Fix: 2023.12.6+
Fix from $1,600 2024-02-29
Hoppscotch HIGH 8.8
CVE-2023-34097

hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the d…

Fix: 2023.4.5+
Fix from $1,950 2023-06-05
Hoppscotch HIGH 8.0
CVE-2022-0121

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue aff…

Fix: after 2.1.0
Fix from $1,950 2022-01-06