Hoppscotch is an open-source API development and testing platform whose vulnerability profile concentrates in its core tool and skews strongly toward critical-severity outcomes. The recurring weakness classes—cross-site scripting, authorization bypass, open redirects, improper access control, and improper authentication—reflect the web-application nature of the platform and the trust boundaries inherent in developer tooling that handles API credentials and requests. Defenders relying on Hoppscotch should monitor vendor releases closely and treat authentication and input-handling disclosures as high-priority; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hoppscotch over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50160CRITICAL Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpo | Jul 1, 2026 | 10.0 | 50 | NO | NO |
CVE-2026-34931CRITICAL hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the | Apr 2, 2026 | 9.6 | 36 | NO | NO |
CVE-2026-34847MEDIUM hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is | Apr 2, 2026 | 6.1 | 33 | NO | YES |
CVE-2026-28215CRITICAL hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hoste | Feb 26, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-34932CRITICAL hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version | Apr 2, 2026 | 9.3 | 31 | NO | NO |
CVE-2026-28216HIGH hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-en | Feb 26, 2026 | 8.3 | 28 | NO | NO |
CVE-2026-28217MEDIUM hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection ID and returns the full collec | Feb 26, 2026 | 6.5 | 24 | NO | NO |
CVE-2023-34097HIGH hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Atta | Jun 5, 2023 | 8.8 | 24 | NO | NO |
CVE-2026-34848MEDIUM hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This is | Apr 2, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-30825MEDIUM hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other us | Mar 7, 2026 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hoppscotch.
Media articles that mention a CVE ID that affects a product developed by Hoppscotch — matched by CVE ID, not by vendor name.