Smartbear develops a focused suite of API testing, design, and quality-assurance tools—including Swagger UI, SoapUI, ReadyAPI, and Zephyr Enterprise—that are embedded across development and QA pipelines, particularly in organizations practicing API-first development. Despite a narrow product portfolio, this vendor's prominence in the landscape reflects the centrality of these tools to modern software delivery workflows and their exposure to untrusted input from both developers and external API interactions. Vulnerabilities affecting Smartbear skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency to acquire public exploit code; the exposure recurs through code-injection flaws, cross-site scripting, deserialization issues, and insecure temporary-file handling that are characteristic of tools processing and executing external specifications and payloads. Defenders should treat updates for these tools with priority commensurate with their role in build and test infrastructure, since compromise can propagate to downstream artifacts and deployments. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartbear over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25031MEDIUM Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability t | Mar 11, 2022 | 4.3 | 50 | NO | YES |
CVE-2018-20580HIGH The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | May 3, 2019 | 8.8 | 43 | NO | YES |
CVE-2014-1202HIGH The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | Jan 25, 2014 | 9.3 | 36 | NO | YES |
CVE-2020-12835CRITICAL An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious seriali | May 20, 2020 | 9.8 | 34 | NO | NO |
CVE-2019-17495CRITICAL A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input f | Oct 10, 2019 | 9.8 | 33 | NO | NO |
CVE-2023-22889CRITICAL SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users. | Mar 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2020-26118HIGH In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's | Jan 11, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-12180HIGH An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allow | Feb 5, 2020 | 7.8 | 27 | NO | NO |
CVE-2024-22207MEDIUM fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in t | Jan 15, 2024 | 5.3 | 26 | NO | YES |
CVE-2017-16670HIGH The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file. | Feb 19, 2018 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartbear.
Media articles that mention a CVE ID that affects a product developed by Smartbear — matched by CVE ID, not by vendor name.