Hubspot's vulnerability profile centers on its marketing automation and customer relationship management platform, with a niche but strategically important attack surface. The recurring exposure reflects template-injection and web-rendering weaknesses—including improper neutralization of special elements in template engines, cross-site scripting, and cleartext transmission of sensitive data—alongside authorization and access-control gaps typical of web-based SaaS applications. Vulnerabilities affecting the vendor skew strongly toward critical severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hubspot over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59340CRITICAL jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical | Sep 17, 2025 | 10.0 | 37 | NO | NO |
CVE-2026-25526CRITICAL JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Ja | Feb 4, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-57736HIGH Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data.
This issue affects HubSpot: from n/a through 11.3.51. | Jul 1, 2026 | 7.4 | 32 | NO | NO |
CVE-2017-16035HIGH The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code tha | Jun 4, 2018 | 8.1 | 24 | NO | NO |
CVE-2022-1239HIGH The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default cont | May 2, 2022 | 8.8 | 23 | NO | NO |
CVE-2020-12668MEDIUM Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, | Feb 19, 2021 | 6.5 | 22 | NO | NO |
CVE-2018-18893MEDIUM Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java. | Jan 3, 2019 | 5.3 | 20 | NO | NO |
CVE-2024-5879MEDIUM The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Wi | Aug 30, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hubspot.
Media articles that mention a CVE ID that affects a product developed by Hubspot — matched by CVE ID, not by vendor name.