Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-6832
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for acc…
Api Control Plane
No fix yet
MEDIUM 5.8
CVE-2024-10302
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data…
Api Control Plane
No fix yet
MEDIUM 5.4
CVE-2025-12624
Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation all…
Identity Server
Mitigation only
MEDIUM 6.1
CVE-2025-6024
The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection.
An attacker can l…
Api Manager
Mitigation only
HIGH 7.2
CVE-2025-13590
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST A…
Api Control Plane
Mitigation only
HIGH 7.2
CVE-2025-12107
Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template…
Identity Server
Mitigation only
CRITICAL 9.8
CVE-2025-9312
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multi…
Api Control Plane
Mitigation only
HIGH 8.8
CVE-2025-6670
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operation…
Api Control Plane
Mitigation only
MEDIUM 6.1
CVE-2025-10853
A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By t…
Api Control Plane
Mitigation only
MEDIUM 6.1
CVE-2025-5770
A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encodin…
Api Control Plane
Mitigation only
HIGH 7.2
CVE-2025-10907
An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP ad…
Api Control Plane
Mitigation only
CRITICAL 9.1
CVE-2025-10713
An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses u…
Api Control Plane
Mitigation only
HIGH 7.2
CVE-2025-3125
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpo…
Api Control Plane
Mitigation only
MEDIUM 5.3
CVE-2025-5605
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can m…
Api Control Plane
Mitigation only
MEDIUM 6.5
CVE-2025-9804
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin S…
Api Control Plane
Mitigation only
MEDIUM 5.7
CVE-2025-9955
An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP ad…
Enterprise Integrator
Mitigation only
CRITICAL 9.8
CVE-2025-9152
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-op…
Api Control Plane
Mitigation only
CRITICAL 9.8
CVE-2025-10611
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be …
Api Control Plane
Mitigation only
HIGH 7.2
CVE-2025-1862
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SO…
Enterprise Integrator
Mitigation only
MEDIUM 5.3
CVE-2025-1396
A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system return…
Identity Server
Mitigation only
MEDIUM 6.1
CVE-2025-0209
A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding.…
Identity Server
Mitigation only
MEDIUM 6.8
CVE-2025-0663
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A singl…
Identity Server
Mitigation only
HIGH 7.2
CVE-2025-5717
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor a…
Api Control Plane
Mitigation only
MEDIUM 6.5
CVE-2024-7073
A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This fla…
Identity Server
Mitigation only
MEDIUM 5.2
CVE-2024-8008
A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated…
Api Manager
Mitigation only
MEDIUM 6.1
CVE-2024-1440
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint …
Api Manager
Mitigation only
MEDIUM 5.4
CVE-2024-7096
A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can crea…
Api Manager
Mitigation only
MEDIUM 6.1
CVE-2024-5962
A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding o…
Api Manager
Mitigation only
MEDIUM 5.8
CVE-2024-7487
An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to …
Identity Server
Mitigation only
MEDIUM 5.4
CVE-2024-7103
A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input va…
Identity Server
Mitigation only