Vulnerabilities (CVE)

Filtered by vendor Smartbear Subscribe
Filtered by product Swagger Ui
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-25031 1 Smartbear 1 Swagger Ui 2022-06-03 4.3 MEDIUM 4.3 MEDIUM
Swagger UI before 4.1.3 could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions.
CVE-2021-46708 1 Smartbear 1 Swagger Ui 2022-06-01 4.3 MEDIUM 6.1 MEDIUM
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.