Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Api Control Plane MEDIUM 6.1
CVE-2025-5770

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encodin…

Mitigation only
Fix from $1,600 2025-11-05
Api Control Plane HIGH 7.2
CVE-2025-11093

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Media…

Fix: 3.1.0.345 / 3.2.0.446+
Fix from $1,950 2025-11-05
Api Control Plane HIGH 7.2
CVE-2025-10907

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP ad…

Mitigation only
Fix from $1,950 2025-11-05
Api Control Plane CRITICAL 9.1
CVE-2025-10713

An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses u…

Mitigation only
Fix from $2,300 2025-11-05
Api Control Plane HIGH 7.2
CVE-2025-3125

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpo…

Mitigation only
Fix from $1,950 2025-11-05
Api Control Plane MEDIUM 5.3
CVE-2025-5605

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can m…

Mitigation only
Fix from $1,600 2025-10-24
Api Control Plane MEDIUM 6.5
CVE-2025-9804

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin S…

Mitigation only
Fix from $1,600 2025-10-16
Enterprise Integrator MEDIUM 5.7
CVE-2025-9955

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP ad…

Mitigation only
Fix from $1,600 2025-10-16
Api Control Plane CRITICAL 9.8
CVE-2025-9152

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-op…

Mitigation only
Fix from $2,300 2025-10-16
Api Control Plane CRITICAL 9.8
CVE-2025-10611

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be …

Mitigation only
Fix from $2,300 2025-10-16
Enterprise Integrator HIGH 7.2
CVE-2025-1862

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SO…

Mitigation only
Fix from $1,950 2025-09-26
Identity Server MEDIUM 5.3
CVE-2025-1396

A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system return…

Mitigation only
Fix from $1,600 2025-09-26
Identity Server MEDIUM 6.1
CVE-2025-0209

A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding.…

Mitigation only
Fix from $1,600 2025-09-23
Identity Server MEDIUM 6.8
CVE-2025-0663

A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A singl…

Mitigation only
Fix from $1,600 2025-09-23
Api Control Plane HIGH 7.2
CVE-2025-5717

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor a…

Mitigation only
Fix from $1,950 2025-09-23
Api Manager MEDIUM 6.5
CVE-2024-4598

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users m…

Fix: 1.2.0.157 / 3.2.0.422+
Fix from $1,600 2025-09-23
Identity Server MEDIUM 6.5
CVE-2024-7073

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This fla…

Mitigation only
Fix from $1,600 2025-06-02
Api Manager MEDIUM 5.2
CVE-2024-8008

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated…

Mitigation only
Fix from $1,600 2025-06-02
Api Manager MEDIUM 6.1
CVE-2024-1440

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint …

Mitigation only
Fix from $1,600 2025-06-02
Api Manager MEDIUM 5.4
CVE-2024-7096

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can crea…

Mitigation only
Fix from $1,600 2025-05-30
Api Manager MEDIUM 6.1
CVE-2024-5962

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding o…

Mitigation only
Fix from $1,600 2025-05-22
Identity Server MEDIUM 5.8
CVE-2024-7487

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to …

Mitigation only
Fix from $1,600 2025-05-22
Identity Server MEDIUM 5.4
CVE-2024-7103

A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input va…

Mitigation only
Fix from $1,600 2025-05-22
Api Manager CRITICAL 9.8
CVE-2024-6914

An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin ser…

Mitigation only
Fix from $2,300 2025-05-22
Api Manager CRITICAL 9.1
CVE-2025-2905

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (…

Fix: after 2.0.0
Fix from $2,300 2025-05-05
Api Manager MEDIUM 6.1
CVE-2024-5848

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper input validation. User-supplied data is directl…

Mitigation only
Fix from $1,600 2025-02-27
Enterprise Integrator MEDIUM 5.4
CVE-2024-0392

A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF tok…

Mitigation only
Fix from $1,600 2025-02-27
Api Manager MEDIUM 5.6
CVE-2024-2321

An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token inst…

Mitigation only
Fix from $1,600 2025-02-27
Api Manager MEDIUM 5.3
CVE-2023-6839

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP re…

Mitigation only
Fix from $1,600 2023-12-15
Api Manager MEDIUM 6.1
CVE-2023-6838

Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated…

Mitigation only
Fix from $1,600 2023-12-15