hoppscotch
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 6, 2022 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server
Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
[CVE-2026-50160] Hoppscotch: Unauthenticated JWT Sect Overwrite (CVSS 10.0)
CVE-2026-50160: Four Independent Weaknesses Combine Into a CVSS 10.0 Full Compromise in Hoppscotch
hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token
hoppscotch: Improper loopback redirect_uri validation in device-login flow
hoppscotch: Stored XSS in team member overflow tooltip via display name
hoppscotch: Stored XSS via mock server responses on backend origin
hoppscotch: Open redirect via `/enter?redirect=`
Monitor hoppscotch in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.