Wiremock

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 6
    Known Exploited: 0
    2
    Critical Level Threats
    0
    High Level Threats
    3
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-50069

    WireMock with GUI versions 3.2.0.0 through 3.0.4.0 are vulnerable to stored cross-site scripting (SXSS) through the recording feature. An attacker can host a malicious payload and perform a test mapping pointing to the attacker's file, and the result will render on the Matched page in the Body area, resulting in the execution of the payload. This occurs because the response body is not validated or sanitized.

    Last Modified: Nov 21, 2024
    Published: Dec 29, 2023

    CVE-2023-39967

    Full read and controlled SSRF through URL parameter when testing a request inside wiremock-studio

    Last Modified: Nov 21, 2024
    Published: Sep 06, 2023

    CVE-2023-41327

    Controlled SSRF through URL in the WireMock

    Last Modified: Nov 21, 2024
    Published: Sep 06, 2023

    CVE-2023-41329

    Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio

    Last Modified: Nov 21, 2024
    Published: Sep 06, 2023

    CVE-2018-9116

    An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentially cause a Denial of Service.

    Last Modified: Nov 21, 2024
    Published: Mar 29, 2018
    Items Per Page
    Wiremock Vulnerabilities & Security CVEs | CVE-DB