Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Api Manager CRITICAL 9.8
CVE-2024-6914

An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin ser…

Mitigation only
Fix from $2,300 2025-05-22
Api Manager MEDIUM 6.1
CVE-2024-5848

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper input validation. User-supplied data is directl…

Mitigation only
Fix from $1,600 2025-02-27
Enterprise Integrator MEDIUM 5.4
CVE-2024-0392

A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF tok…

Mitigation only
Fix from $1,600 2025-02-27
Api Manager MEDIUM 5.6
CVE-2024-2321

An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token inst…

Mitigation only
Fix from $1,600 2025-02-27
Api Manager MEDIUM 5.3
CVE-2023-6839

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP re…

Mitigation only
Fix from $1,600 2023-12-15
Api Manager MEDIUM 6.1
CVE-2023-6838

Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated…

Mitigation only
Fix from $1,600 2023-12-15
Api Manager MEDIUM 5.3
CVE-2023-6835

Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manip…

Mitigation only
Fix from $1,600 2023-12-15
Enterprise Integrator MEDIUM 6.1
CVE-2022-39809

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Manageme…

Mitigation only
Fix from $1,600 2022-09-09
Enterprise Integrator MEDIUM 6.1
CVE-2022-39810EPSS 57%

An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Manageme…

Mitigation only
Fix from $1,600 2022-09-09
Api Manager MEDIUM 6.1
CVE-2022-29548EPSS 41%

A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, a…

No fix yet
Fix from $1,600 2022-04-21
Api Manager MEDIUM 6.1
CVE-2021-36760

In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback …

Mitigation only
Fix from $1,600 2021-12-07
Api Manager MEDIUM 6.1
CVE-2020-27885

Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logg…

No fix yet
Fix from $1,600 2020-10-29
Api Manager CRITICAL 9.8
CVE-2020-13226

WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's en…

Mitigation only
Fix from $2,300 2020-05-20
Api Manager MEDIUM 6.1
CVE-2019-20437

An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a custom claim dialect with an …

No fix yet
Fix from $1,600 2020-01-28
Api Manager MEDIUM 6.1
CVE-2019-20436

An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. If there is a claim dialect configur…

No fix yet
Fix from $1,600 2020-01-28
Api Manager MEDIUM 5.4
CVE-2019-6513

An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing …

Mitigation only
Fix from $1,600 2019-05-21
Dashboard Server MEDIUM 5.8
CVE-2019-6516

An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port…

Mitigation only
Fix from $1,600 2019-05-14
Carbon MEDIUM 6.1
CVE-2016-4316

Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) se…

No fix yet
Fix from $1,600 2017-02-17