Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-5770 A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encodin… Api Control Plane Mitigation only Fix from $1,6002025-11-05 HIGH 7.2 CVE-2025-11093 An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Media… Api Control Plane 3.1.0.345 / 3.2.0.446+ Fix from $1,9502025-11-05 HIGH 7.2 CVE-2025-10907 An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP ad… Api Control Plane Mitigation only Fix from $1,9502025-11-05 CRITICAL 9.1 CVE-2025-10713 An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses u… Api Control Plane Mitigation only Fix from $2,3002025-11-05 HIGH 7.2 CVE-2025-3125 An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpo… Api Control Plane Mitigation only Fix from $1,9502025-11-05 MEDIUM 5.3 CVE-2025-5605 An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can m… Api Control Plane Mitigation only Fix from $1,6002025-10-24 MEDIUM 6.5 CVE-2025-9804 An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin S… Api Control Plane Mitigation only Fix from $1,6002025-10-16 MEDIUM 5.7 CVE-2025-9955 An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP ad… Enterprise Integrator Mitigation only Fix from $1,6002025-10-16 CRITICAL 9.8 CVE-2025-9152 An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-op… Api Control Plane Mitigation only Fix from $2,3002025-10-16 CRITICAL 9.8 CVE-2025-10611 Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be … Api Control Plane Mitigation only Fix from $2,3002025-10-16 HIGH 7.2 CVE-2025-1862 An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SO… Enterprise Integrator Mitigation only Fix from $1,9502025-09-26 MEDIUM 5.3 CVE-2025-1396 A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system return… Identity Server Mitigation only Fix from $1,6002025-09-26 MEDIUM 6.1 CVE-2025-0209 A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding.… Identity Server Mitigation only Fix from $1,6002025-09-23 MEDIUM 6.8 CVE-2025-0663 A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A singl… Identity Server Mitigation only Fix from $1,6002025-09-23 HIGH 7.2 CVE-2025-5717 An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor a… Api Control Plane Mitigation only Fix from $1,9502025-09-23 MEDIUM 6.5 CVE-2024-4598 An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users m… Api Manager 1.2.0.157 / 3.2.0.422+ Fix from $1,6002025-09-23 MEDIUM 6.5 CVE-2024-7073 A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This fla… Identity Server Mitigation only Fix from $1,6002025-06-02 MEDIUM 5.2 CVE-2024-8008 A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated… Api Manager Mitigation only Fix from $1,6002025-06-02 MEDIUM 6.1 CVE-2024-1440 An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint … Api Manager Mitigation only Fix from $1,6002025-06-02 MEDIUM 5.4 CVE-2024-7096 A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can crea… Api Manager Mitigation only Fix from $1,6002025-05-30 MEDIUM 6.1 CVE-2024-5962 A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding o… Api Manager Mitigation only Fix from $1,6002025-05-22 MEDIUM 5.8 CVE-2024-7487 An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to … Identity Server Mitigation only Fix from $1,6002025-05-22 MEDIUM 5.4 CVE-2024-7103 A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input va… Identity Server Mitigation only Fix from $1,6002025-05-22 CRITICAL 9.8 CVE-2024-6914 An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin ser… Api Manager Mitigation only Fix from $2,3002025-05-22 CRITICAL 9.1 CVE-2025-2905 Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (… Api Manager after 2.0.0 Fix from $2,3002025-05-05 MEDIUM 6.1 CVE-2024-5848 A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper input validation. User-supplied data is directl… Api Manager Mitigation only Fix from $1,6002025-02-27 MEDIUM 5.4 CVE-2024-0392 A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF tok… Enterprise Integrator Mitigation only Fix from $1,6002025-02-27 MEDIUM 5.6 CVE-2024-2321 An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token inst… Api Manager Mitigation only Fix from $1,6002025-02-27 MEDIUM 5.3 CVE-2023-6839 Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP re… Api Manager Mitigation only Fix from $1,6002023-12-15 MEDIUM 6.1 CVE-2023-6838 Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated… Api Manager Mitigation only Fix from $1,6002023-12-15