VendorsSmartBearswagger_petstore1.0.7
Vulnerabilities

SmartBear Swagger Petstore 1.0.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-29157
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version
Published 2025-09-25 · Analyzed
6.5EPSS 0.005
CVE-2025-29155
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
Published 2025-09-25 · Analyzed
6.5EPSS 0.004
CVE-2025-29156
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet
Published 2025-09-25 · Analyzed
6.1EPSS 0.004