« Volver al listado

Hoppscotch

Hoppscotch: vulnerabilidades y CVE

Hoppscotch tiene 16 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses13
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-69189Alta (7.6)0.39%—18 ago 2026
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings…
CVE-2026-59721Alta (7.2)1.0%—9 jul 2026
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in…
CVE-2026-59720Alta (7.5)0.59%—9 jul 2026
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing…
CVE-2026-50160Crítica (10)1.7%—1 jul 2026
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment.…
CVE-2026-44478Alta (7.5)0.41%—13 may 2026
hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and…
CVE-2026-34932Alta (8.5)0.40%—2 abr 2026
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.
CVE-2026-34931Alta (8.5)0.43%—2 abr 2026
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim to…
CVE-2026-34848Media (5.4)0.24%—2 abr 2026
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This issue has been patched in version…
CVE-2026-34847Media (6.1)0.46%—2 abr 2026
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is directly used to construct a URL and…
CVE-2026-30825Media (6.5)0.29%—7 mar 2026
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other user's PAT by providing its ID, with no…
CVE-2026-28217Media (6.5)0.38%—26 feb 2026
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection ID and returns the full collection data — including title, type, and…
CVE-2026-28216Alta (8.3)0.42%—26 feb 2026
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-environments.resolver.ts:82-109`,…
CVE-2026-28215Crítica (9.1)0.66%—26 feb 2026
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth…
CVE-2024-27092Media (5.4)0.61%—29 feb 2024
Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is…
CVE-2023-34097Alta (8.8)0.68%—5 jun 2023
hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Attackers with access to read system logs…
CVE-2022-0121Alta (8)1.2%—6 ene 2022
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1005 Data from Local System3
  3. T1210 Exploitation of Remote Services3
  4. T1078 Valid Accounts2
  5. T1189 Drive-by Compromise2
  6. T1059 Command and Scripting Interpreter1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Hoppscotch