Vulnerabilities (CVE)

Filtered by vendor Smartbear Subscribe
Filtered by product Swagger Petstore
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29156 1 Smartbear 1 Swagger Petstore 2025-10-14 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet
CVE-2025-29157 1 Smartbear 1 Swagger Petstore 2025-10-14 N/A 6.5 MEDIUM
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version
CVE-2025-29155 1 Smartbear 1 Swagger Petstore 2025-10-03 N/A 6.5 MEDIUM
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint