Wiremock is a focused mock server and API testing platform with a niche but strategically positioned footprint across testing and development environments, including core server components and language-specific bindings such as Python variants and containerized distributions. Its vulnerabilities skew strongly toward critical-severity outcomes and concentrate in weakness classes characteristic of web-facing services: server-side request forgery, authentication bypass, path traversal, cross-site scripting, and XML external entity injection that can undermine the integrity of test data and expose systems that depend on mocked responses. Defenders deploying this tool should treat advisories as high-priority within development and CI/CD pipelines where test servers may have privileged network access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wiremock over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9116CRITICAL An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentially cause a Denial of Service. | Mar 29, 2018 | 9.1 | 29 | NO | NO |
CVE-2023-39967CRITICAL WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to a | Sep 6, 2023 | 10.0 | 27 | NO | NO |
CVE-2023-41329MEDIUM WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions configuration, as documented in Preventing proxying to and re | Sep 6, 2023 | 6.6 | 21 | NO | NO |
CVE-2018-9117MEDIUM WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application directory via a specially crafted XML req | Mar 29, 2018 | 5.3 | 19 | NO | NO |
CVE-2023-50069MEDIUM WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and | Dec 29, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-41327MEDIUM WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allo | Sep 6, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wiremock.
Media articles that mention a CVE ID that affects a product developed by Wiremock — matched by CVE ID, not by vendor name.