Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 10.0
CVE-2026-5430
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t…
Api Control Plane
4.1.0.257 / 4.2.0.197+
CRITICAL 9.8
CVE-2026-1728
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
Exploitati…
Api Control Plane
4.0.0.384 / 4.1.0.248+
CRITICAL 9.4
CVE-2025-15039
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a…
Api Control Plane
1.4.0.137 / 1.4.0.143+
MEDIUM 5.4
CVE-2025-13394
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Sp…
Api Control Plane
2.0.0.401 / 2.0.0.421+
HIGH 7.5
CVE-2024-6832
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for acc…
Api Control Plane
No fix yet
MEDIUM 5.8
CVE-2024-10302
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data…
Api Control Plane
No fix yet
MEDIUM 6.1
CVE-2026-2445
The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it withi…
Api Control Plane
4.2.0.195 / 4.3.0.106+
HIGH 8.6
CVE-2026-4249
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structur…
Api Control Plane
4.0.0.390 / 4.1.0.254+
MEDIUM 6.1
CVE-2025-8591
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This c…
Api Control Plane
2.0.0.404 / 2.0.0.424+
MEDIUM 5.3
CVE-2024-1248
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account …
Api Manager
2.0.0.313 / 2.0.0.333+
HIGH 7.3
CVE-2025-13475
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent grante…
Api Manager
3.2.0.457 / 3.2.1.76+
CRITICAL 10.0
CVE-2026-2053
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled inpu…
Api Manager
3.1.0.360 / 3.2.0.465+
HIGH 7.2
CVE-2025-9973
Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication …
Identity Server
7.1.0.26+
HIGH 8.6
CVE-2025-10470
The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to un…
Identity Server
7.0.0.121+
HIGH 8.8
CVE-2025-8325
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke thes…
Api Control Plane
3.2.0.435 / 3.2.1.55+
HIGH 7.5
CVE-2025-8154
In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowin…
Api Control Plane
4.1.0.218 / 4.2.0.164+
HIGH 7.3
CVE-2025-10908
Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass…
Identity Server
6.0.0.249 / 6.1.0.248+
MEDIUM 6.1
CVE-2025-10503
The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encodin…
Identity Server
7.1.0.28+
MEDIUM 5.4
CVE-2025-12624
Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation all…
Identity Server
Mitigation only
HIGH 7.5
CVE-2024-8010
The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted …
Api Manager
3.2.0.397 / 3.2.1.27+
MEDIUM 6.1
CVE-2025-6024
The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection.
An attacker can l…
Api Manager
Mitigation only
MEDIUM 5.4
CVE-2024-4867
The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This d…
Api Manager
3.2.0.408 / 3.2.1.32+
MEDIUM 6.1
CVE-2024-10242
The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to in…
Api Manager
3.2.0.401 / 4.0.0.318+
CRITICAL 9.1
CVE-2024-2374
The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entiti…
Api Manager
2.0.0.328 / 2.0.0.348+
HIGH 8.1
CVE-2024-1524
When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user'…
Api Manager
4.2.0.108 / 6.0.0.171+
HIGH 7.2
CVE-2025-13590
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST A…
Api Control Plane
Mitigation only
HIGH 7.2
CVE-2025-12107
Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template…
Identity Server
Mitigation only
CRITICAL 9.8
CVE-2025-9312
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multi…
Api Control Plane
Mitigation only
HIGH 8.8
CVE-2025-6670
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operation…
Api Control Plane
Mitigation only
MEDIUM 6.1
CVE-2025-10853
A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By t…
Api Control Plane
Mitigation only