Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Api Control Plane CRITICAL 10.0
CVE-2026-5430

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t…

Fix: 4.1.0.257 / 4.2.0.197+
Fix from $2,300 2026-08-06
Api Control Plane CRITICAL 9.8
CVE-2026-1728

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitati…

Fix: 4.0.0.384 / 4.1.0.248+
Fix from $2,300 2026-08-06
Api Control Plane CRITICAL 9.4
CVE-2025-15039

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a…

Fix: 1.4.0.137 / 1.4.0.143+
Fix from $2,300 2026-08-06
Api Control Plane MEDIUM 5.4
CVE-2025-13394

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Sp…

Fix: 2.0.0.401 / 2.0.0.421+
Fix from $1,600 2026-08-06
Api Control Plane HIGH 7.5
CVE-2024-6832

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for acc…

No fix yet
Fix from $1,950 2026-08-06
Api Control Plane MEDIUM 5.8
CVE-2024-10302

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data…

No fix yet
Fix from $1,600 2026-08-06
Api Control Plane MEDIUM 6.1
CVE-2026-2445

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it withi…

Fix: 4.2.0.195 / 4.3.0.106+
Fix from $1,600 2026-07-20
Api Control Plane HIGH 8.6
CVE-2026-4249

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structur…

Fix: 4.0.0.390 / 4.1.0.254+
Fix from $1,950 2026-07-06
Api Control Plane MEDIUM 6.1
CVE-2025-8591

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This c…

Fix: 2.0.0.404 / 2.0.0.424+
Fix from $1,600 2026-07-06
Api Manager MEDIUM 5.3
CVE-2024-1248

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account …

Fix: 2.0.0.313 / 2.0.0.333+
Fix from $1,600 2026-07-04
Api Manager HIGH 7.3
CVE-2025-13475

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent grante…

Fix: 3.2.0.457 / 3.2.1.76+
Fix from $1,950 2026-07-04
Api Manager CRITICAL 10.0
CVE-2026-2053

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled inpu…

Fix: 3.1.0.360 / 3.2.0.465+
Fix from $2,300 2026-06-26
Identity Server HIGH 7.2
CVE-2025-9973

Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication …

Fix: 7.1.0.26+
Fix from $1,950 2026-05-11
Identity Server HIGH 8.6
CVE-2025-10470

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to un…

Fix: 7.0.0.121+
Fix from $1,950 2026-05-11
Api Control Plane HIGH 8.8
CVE-2025-8325

The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke thes…

Fix: 3.2.0.435 / 3.2.1.55+
Fix from $1,950 2026-05-11
Api Control Plane HIGH 7.5
CVE-2025-8154

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowin…

Fix: 4.1.0.218 / 4.2.0.164+
Fix from $1,950 2026-05-11
Identity Server HIGH 7.3
CVE-2025-10908

Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass…

Fix: 6.0.0.249 / 6.1.0.248+
Fix from $1,950 2026-05-11
Identity Server MEDIUM 6.1
CVE-2025-10503

The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encodin…

Fix: 7.1.0.28+
Fix from $1,600 2026-04-29
Identity Server MEDIUM 5.4
CVE-2025-12624

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation all…

Mitigation only
Fix from $1,600 2026-04-16
Api Manager HIGH 7.5
CVE-2024-8010

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted …

Fix: 3.2.0.397 / 3.2.1.27+
Fix from $1,950 2026-04-16
Api Manager MEDIUM 6.1
CVE-2025-6024

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can l…

Mitigation only
Fix from $1,600 2026-04-16
Api Manager MEDIUM 5.4
CVE-2024-4867

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This d…

Fix: 3.2.0.408 / 3.2.1.32+
Fix from $1,600 2026-04-16
Api Manager MEDIUM 6.1
CVE-2024-10242

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to in…

Fix: 3.2.0.401 / 4.0.0.318+
Fix from $1,600 2026-04-16
Api Manager CRITICAL 9.1
CVE-2024-2374

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entiti…

Fix: 2.0.0.328 / 2.0.0.348+
Fix from $2,300 2026-04-16
Api Manager HIGH 8.1
CVE-2024-1524

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user'…

Fix: 4.2.0.108 / 6.0.0.171+
Fix from $1,950 2026-02-24
Api Control Plane HIGH 7.2
CVE-2025-13590

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST A…

Mitigation only
Fix from $1,950 2026-02-19
Identity Server HIGH 7.2
CVE-2025-12107

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template…

Mitigation only
Fix from $1,950 2026-02-19
Api Control Plane CRITICAL 9.8
CVE-2025-9312

A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multi…

Mitigation only
Fix from $2,300 2025-11-18
Api Control Plane HIGH 8.8
CVE-2025-6670

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operation…

Mitigation only
Fix from $1,950 2025-11-18
Api Control Plane MEDIUM 6.1
CVE-2025-10853

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By t…

Mitigation only
Fix from $1,600 2025-11-05