Portswigger maintains a focused portfolio centered on Burp Suite, a widely deployed web-application security testing platform used by penetration testers and security researchers to identify vulnerabilities in web services. The observed weakness classes in the vendor's disclosure history center on certificate validation, permission assignment, and URL redirection handling, reflecting the authentication and traffic-inspection demands of a proxy-based security tool. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Portswigger over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44230MEDIUM PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can | Nov 30, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-29416MEDIUM An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstr | Mar 29, 2021 | 6.5 | 22 | NO | NO |
CVE-2018-1153HIGH Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic. | Jun 18, 2018 | 7.4 | 22 | NO | NO |
CVE-2018-10377MEDIUM PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle attackers to obtain interaction | Jun 17, 2018 | 5.9 | 20 | NO | NO |
CVE-2022-35406MEDIUM A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect. | Jul 8, 2022 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Portswigger.
Media articles that mention a CVE ID that affects a product developed by Portswigger — matched by CVE ID, not by vendor name.