Technology · npm
swagger-ui (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in swagger-ui (npm): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2016-1000229, was published on 24 May 2022.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About swagger-ui (npm)
A collection of HTML, JavaScript, and CSS assets that dynamically generate documentation from a Swagger-compliant API.
Latest swagger-ui (npm) vulnerabilities
- CVE-2016-1000229: swagger-ui cross-site scripting in key nameslowCVSS 3.1EPSS 4.0%
- CVE-2018-25031: Swagger UI spoofing attack via URL parameterlowCVSS 3.1EPSS 42.3%
- Swagger UI phishing vector via URL parameterinfoCVSS 6.5
- Swagger UI Cross-Site Scripting in apiInfo.descriptioninfo
- Swagger Swagger UI Cross-Site Scripting in API response renderinginfoCVSS 6.1
- Swagger UI Cross-Site Scripting in method descriptionsinfo
- Swagger UI cross-site scripting in OAuth URL handlinglowCVSS 3.1
- Swagger swagger-ui Cross-Site Scripting in YAML description fieldlowCVSS 3.1
- Swagger UI cross-site scripting via URL parameterinfo
- CVE-2016-1000233: Swagger UI cross-site scripting via url parameterinfoCVSS 0
- CVE-2016-5682: swagger-ui cross-site scripting in property namesinfoCVSS 0EPSS 1.0%
- CVE-2016-1000226: Swagger UI cross-site scripting in swagger JSON parametersinfo
- CVE-2019-17495: Swagger-UI CSS injection via Relative Path OverwritelowCVSS 3.1EPSS 5.7%
- Swagger UI reverse tabnapping in anchor tagslowCVSS 3.1
Most severe swagger-ui (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2018-25031: Swagger UI spoofing attack via URL parameterlowCVSS 3.1EPSS 42.3%
- CVE-2019-17495: Swagger-UI CSS injection via Relative Path OverwritelowCVSS 3.1EPSS 5.7%
- CVE-2016-1000229: swagger-ui cross-site scripting in key nameslowCVSS 3.1EPSS 4.0%
- Swagger swagger-ui Cross-Site Scripting in YAML description fieldlowCVSS 3.1
- Swagger UI cross-site scripting in OAuth URL handlinglowCVSS 3.1
- Swagger UI reverse tabnapping in anchor tagslowCVSS 3.1
- Swagger UI phishing vector via URL parameterinfoCVSS 6.5
- Swagger Swagger UI Cross-Site Scripting in API response renderinginfoCVSS 6.1
- CVE-2016-5682: swagger-ui cross-site scripting in property namesinfoCVSS 0EPSS 1.0%
- CVE-2016-1000233: Swagger UI cross-site scripting via url parameterinfoCVSS 0
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/swagger-ui.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "swagger-ui (npm) vulnerabilities", https://junglewise.ai/threats/technologies/swagger-ui, 26 September 2026.