Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-5430 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t… Api Control Plane 4.1.0.257 / 4.2.0.197+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-1728 Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitati… Api Control Plane 4.0.0.384 / 4.1.0.248+ Fix from $2,3002026-08-06 CRITICAL 9.4 CVE-2025-15039 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a… Api Control Plane 1.4.0.137 / 1.4.0.143+ Fix from $2,3002026-08-06 MEDIUM 5.4 CVE-2025-13394 The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Sp… Api Control Plane 2.0.0.401 / 2.0.0.421+ Fix from $1,6002026-08-06 HIGH 7.5 CVE-2024-6832 The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for acc… Api Control Plane No fix yet Fix from $1,9502026-08-06 MEDIUM 5.8 CVE-2024-10302 The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data… Api Control Plane No fix yet Fix from $1,6002026-08-06 MEDIUM 6.1 CVE-2026-2445 The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it withi… Api Control Plane 4.2.0.195 / 4.3.0.106+ Fix from $1,6002026-07-20 HIGH 8.6 CVE-2026-4249 The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structur… Api Control Plane 4.0.0.390 / 4.1.0.254+ Fix from $1,9502026-07-06 MEDIUM 6.1 CVE-2025-8591 The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This c… Api Control Plane 2.0.0.404 / 2.0.0.424+ Fix from $1,6002026-07-06 MEDIUM 5.3 CVE-2024-1248 The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account … Api Manager 2.0.0.313 / 2.0.0.333+ Fix from $1,6002026-07-04 HIGH 7.3 CVE-2025-13475 In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent grante… Api Manager 3.2.0.457 / 3.2.1.76+ Fix from $1,9502026-07-04 CRITICAL 10.0 CVE-2026-2053 The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled inpu… Api Manager 3.1.0.360 / 3.2.0.465+ Fix from $2,3002026-06-26 HIGH 7.2 CVE-2025-9973 Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication … Identity Server 7.1.0.26+ Fix from $1,9502026-05-11 HIGH 8.6 CVE-2025-10470 The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to un… Identity Server 7.0.0.121+ Fix from $1,9502026-05-11 HIGH 8.8 CVE-2025-8325 The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke thes… Api Control Plane 3.2.0.435 / 3.2.1.55+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2025-8154 In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowin… Api Control Plane 4.1.0.218 / 4.2.0.164+ Fix from $1,9502026-05-11 HIGH 7.3 CVE-2025-10908 Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass… Identity Server 6.0.0.249 / 6.1.0.248+ Fix from $1,9502026-05-11 MEDIUM 6.1 CVE-2025-10503 The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encodin… Identity Server 7.1.0.28+ Fix from $1,6002026-04-29 MEDIUM 5.4 CVE-2025-12624 Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation all… Identity Server Mitigation only Fix from $1,6002026-04-16 HIGH 7.5 CVE-2024-8010 The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted … Api Manager 3.2.0.397 / 3.2.1.27+ Fix from $1,9502026-04-16 MEDIUM 6.1 CVE-2025-6024 The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can l… Api Manager Mitigation only Fix from $1,6002026-04-16 MEDIUM 5.4 CVE-2024-4867 The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This d… Api Manager 3.2.0.408 / 3.2.1.32+ Fix from $1,6002026-04-16 MEDIUM 6.1 CVE-2024-10242 The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to in… Api Manager 3.2.0.401 / 4.0.0.318+ Fix from $1,6002026-04-16 CRITICAL 9.1 CVE-2024-2374 The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entiti… Api Manager 2.0.0.328 / 2.0.0.348+ Fix from $2,3002026-04-16 HIGH 8.1 CVE-2024-1524 When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user'… Api Manager 4.2.0.108 / 6.0.0.171+ Fix from $1,9502026-02-24 HIGH 7.2 CVE-2025-13590 A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST A… Api Control Plane Mitigation only Fix from $1,9502026-02-19 HIGH 7.2 CVE-2025-12107 Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template… Identity Server Mitigation only Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2025-9312 A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multi… Api Control Plane Mitigation only Fix from $2,3002025-11-18 HIGH 8.8 CVE-2025-6670 A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operation… Api Control Plane Mitigation only Fix from $1,9502025-11-18 MEDIUM 6.1 CVE-2025-10853 A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By t… Api Control Plane Mitigation only Fix from $1,6002025-11-05