Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hoppscotch

First CVE: Jan 6, 2022Active for: 5 yearsTotal CVEs: 12
52.5
VTI Score
TOP TARGET

Hoppscotch is an open-source API development and testing platform whose vulnerability profile concentrates in its core tool and skews strongly toward critical-severity outcomes. The recurring weakness classes—cross-site scripting, authorization bypass, open redirects, improper access control, and improper authentication—reflect the web-application nature of the platform and the trust boundaries inherent in developer tooling that handles API credentials and requests. Defenders relying on Hoppscotch should monitor vendor releases closely and treat authentication and input-handling disclosures as high-priority; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hoppscotch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 6, 2022
4 years ago
Most Recent CVE
Jul 1, 2026
24 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-50160CRITICAL
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpo
Jul 1, 202610.050NONO
CVE-2026-34931CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the
Apr 2, 20269.636NONO
CVE-2026-34847MEDIUM
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is
Apr 2, 20266.133NOYES
CVE-2026-28215CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hoste
Feb 26, 20269.132NONO
CVE-2026-34932CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version
Apr 2, 20269.331NONO
CVE-2026-28216HIGH
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-en
Feb 26, 20268.328NONO
CVE-2026-28217MEDIUM
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection ID and returns the full collec
Feb 26, 20266.524NONO
CVE-2023-34097HIGH
hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Atta
Jun 5, 20238.824NONO
CVE-2026-34848MEDIUM
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This is
Apr 2, 20265.421NONO
CVE-2026-30825MEDIUM
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other us
Mar 7, 20266.520NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
25%
33%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (50.0%)
Unknown0 (0.0%)
Required6 (50.0%)
Privileges Required
Low7 (58.3%)
High0 (0.0%)
None5 (41.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hoppscotch.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hoppscotch — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hoppscotch's Products

View all 2 CNAs →

Top CWEs