Hoppscotch
9 known vulnerabilities
Top Products
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and e
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability t
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerabili
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability i
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke e
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query ac
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overw
Frequently Asked Questions
How many CVEs affect Hoppscotch?
Hoppscotch has 9 CVE records in our database, including 4 critical and 1 high severity vulnerabilities.
What are the most severe Hoppscotch vulnerabilities?
Hoppscotch has 4 critical severity (CVSS 9.0+) and 1 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Hoppscotch vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Hoppscotch products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Hoppscotch Vulnerabilities
CyberStrike scans your infrastructure for Hoppscotch vulnerabilities and provides real-time remediation guidance.
Get Started