Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-6914 An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin ser… Api Manager Mitigation only Fix from $2,3002025-05-22 MEDIUM 6.1 CVE-2024-5848 A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper input validation. User-supplied data is directl… Api Manager Mitigation only Fix from $1,6002025-02-27 MEDIUM 5.4 CVE-2024-0392 A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF tok… Enterprise Integrator Mitigation only Fix from $1,6002025-02-27 MEDIUM 5.6 CVE-2024-2321 An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token inst… Api Manager Mitigation only Fix from $1,6002025-02-27 MEDIUM 5.3 CVE-2023-6839 Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP re… Api Manager Mitigation only Fix from $1,6002023-12-15 MEDIUM 6.1 CVE-2023-6838 Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated… Api Manager Mitigation only Fix from $1,6002023-12-15 MEDIUM 5.3 CVE-2023-6835 Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manip… Api Manager Mitigation only Fix from $1,6002023-12-15 MEDIUM 6.1 CVE-2022-39809 An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Manageme… Enterprise Integrator Mitigation only Fix from $1,6002022-09-09 MEDIUM 6.1 CVE-2022-39810EPSS 57% An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Manageme… Enterprise Integrator Mitigation only Fix from $1,6002022-09-09 MEDIUM 6.1 CVE-2022-29548EPSS 41% A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, a… Api Manager No fix yet Fix from $1,6002022-04-21 MEDIUM 6.1 CVE-2021-36760 In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback … Api Manager Mitigation only Fix from $1,6002021-12-07 MEDIUM 6.1 CVE-2020-27885 Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logg… Api Manager No fix yet Fix from $1,6002020-10-29 CRITICAL 9.8 CVE-2020-13226 WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's en… Api Manager Mitigation only Fix from $2,3002020-05-20 MEDIUM 6.1 CVE-2019-20437 An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a custom claim dialect with an … Api Manager No fix yet Fix from $1,6002020-01-28 MEDIUM 6.1 CVE-2019-20436 An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. If there is a claim dialect configur… Api Manager No fix yet Fix from $1,6002020-01-28 MEDIUM 5.4 CVE-2019-6513 An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing … Api Manager Mitigation only Fix from $1,6002019-05-21 MEDIUM 5.8 CVE-2019-6516 An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port… Dashboard Server Mitigation only Fix from $1,6002019-05-14 MEDIUM 6.1 CVE-2016-4316 Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) se… Carbon No fix yet Fix from $1,6002017-02-17