Known CVE
Hoppscotch <= 2026.2.1 - Open Redirect
Hoppscotch <= 2026.2.1 is vulnerable to a DOM-based open redirect on the /enter page. The redirect query parameter is passed directly to windowz location.href with no origin validation. Requires one additional query parameter to trigger. Exploited via a crafted URL such as /enter?redirect=evil.com&foo=bar.
CVE-2026-34847
Medium2026CVSS 4.7CWE-601
cve2026 · hoppscotch · redirect
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website