Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Smartbear

First CVE: Jan 25, 2014Active for: 12 yearsTotal CVEs: 23
50.9
VTI Score
TOP TARGET

Smartbear develops a focused suite of API testing, design, and quality-assurance tools—including Swagger UI, SoapUI, ReadyAPI, and Zephyr Enterprise—that are embedded across development and QA pipelines, particularly in organizations practicing API-first development. Despite a narrow product portfolio, this vendor's prominence in the landscape reflects the centrality of these tools to modern software delivery workflows and their exposure to untrusted input from both developers and external API interactions. Vulnerabilities affecting Smartbear skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency to acquire public exploit code; the exposure recurs through code-injection flaws, cross-site scripting, deserialization issues, and insecure temporary-file handling that are characteristic of tools processing and executing external specifications and payloads. Defenders should treat updates for these tools with priority commensurate with their role in build and test infrastructure, since compromise can propagate to downstream artifacts and deployments. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Smartbear over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2014
12 years ago
Most Recent CVE
Sep 25, 2025
302 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-25031MEDIUM
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability t
Mar 11, 20224.350NOYES
CVE-2018-20580HIGH
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
May 3, 20198.843NOYES
CVE-2014-1202HIGH
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
Jan 25, 20149.336NOYES
CVE-2020-12835CRITICAL
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious seriali
May 20, 20209.834NONO
CVE-2019-17495CRITICAL
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input f
Oct 10, 20199.833NONO
CVE-2023-22889CRITICAL
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
Mar 8, 20239.829NONO
CVE-2020-26118HIGH
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's
Jan 11, 20218.827NONO
CVE-2019-12180HIGH
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allow
Feb 5, 20207.827NONO
CVE-2024-22207MEDIUM
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in t
Jan 15, 20245.326NOYES
CVE-2017-16670HIGH
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
Feb 19, 20187.826NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
43%
43%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (21.7%)
Network17 (73.9%)
Unknown1 (4.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (91.3%)
High1 (4.3%)
Unknown1 (4.3%)
User Interaction
None12 (52.2%)
Unknown1 (4.3%)
Required10 (43.5%)
Privileges Required
Low4 (17.4%)
High0 (0.0%)
None18 (78.3%)
Unknown1 (4.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
8.7% of CVEs· 96th percentile
ExploitDB
2 CVEs
8.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Smartbear.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Smartbear — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Smartbear's Products

View all 4 CNAs →

Top CWEs