Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Api Control Plane HIGH 7.5
CVE-2024-6832

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for acc…

No fix yet
Fix from $1,950 2026-08-06
Api Control Plane MEDIUM 5.8
CVE-2024-10302

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data…

No fix yet
Fix from $1,600 2026-08-06
Identity Server MEDIUM 5.4
CVE-2025-12624

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation all…

Mitigation only
Fix from $1,600 2026-04-16
Api Manager MEDIUM 6.1
CVE-2025-6024

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can l…

Mitigation only
Fix from $1,600 2026-04-16
Api Control Plane HIGH 7.2
CVE-2025-13590

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST A…

Mitigation only
Fix from $1,950 2026-02-19
Identity Server HIGH 7.2
CVE-2025-12107

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template…

Mitigation only
Fix from $1,950 2026-02-19
Api Control Plane CRITICAL 9.8
CVE-2025-9312

A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multi…

Mitigation only
Fix from $2,300 2025-11-18
Api Control Plane HIGH 8.8
CVE-2025-6670

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operation…

Mitigation only
Fix from $1,950 2025-11-18
Api Control Plane MEDIUM 6.1
CVE-2025-10853

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By t…

Mitigation only
Fix from $1,600 2025-11-05
Api Control Plane MEDIUM 6.1
CVE-2025-5770

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encodin…

Mitigation only
Fix from $1,600 2025-11-05
Api Control Plane HIGH 7.2
CVE-2025-10907

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP ad…

Mitigation only
Fix from $1,950 2025-11-05
Api Control Plane CRITICAL 9.1
CVE-2025-10713

An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses u…

Mitigation only
Fix from $2,300 2025-11-05
Api Control Plane HIGH 7.2
CVE-2025-3125

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpo…

Mitigation only
Fix from $1,950 2025-11-05
Api Control Plane MEDIUM 5.3
CVE-2025-5605

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can m…

Mitigation only
Fix from $1,600 2025-10-24
Api Control Plane MEDIUM 6.5
CVE-2025-9804

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin S…

Mitigation only
Fix from $1,600 2025-10-16
Enterprise Integrator MEDIUM 5.7
CVE-2025-9955

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP ad…

Mitigation only
Fix from $1,600 2025-10-16
Api Control Plane CRITICAL 9.8
CVE-2025-9152

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-op…

Mitigation only
Fix from $2,300 2025-10-16
Api Control Plane CRITICAL 9.8
CVE-2025-10611

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be …

Mitigation only
Fix from $2,300 2025-10-16
Enterprise Integrator HIGH 7.2
CVE-2025-1862

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SO…

Mitigation only
Fix from $1,950 2025-09-26
Identity Server MEDIUM 5.3
CVE-2025-1396

A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system return…

Mitigation only
Fix from $1,600 2025-09-26
Identity Server MEDIUM 6.1
CVE-2025-0209

A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding.…

Mitigation only
Fix from $1,600 2025-09-23
Identity Server MEDIUM 6.8
CVE-2025-0663

A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A singl…

Mitigation only
Fix from $1,600 2025-09-23
Api Control Plane HIGH 7.2
CVE-2025-5717

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor a…

Mitigation only
Fix from $1,950 2025-09-23
Identity Server MEDIUM 6.5
CVE-2024-7073

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This fla…

Mitigation only
Fix from $1,600 2025-06-02
Api Manager MEDIUM 5.2
CVE-2024-8008

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated…

Mitigation only
Fix from $1,600 2025-06-02
Api Manager MEDIUM 6.1
CVE-2024-1440

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint …

Mitigation only
Fix from $1,600 2025-06-02
Api Manager MEDIUM 5.4
CVE-2024-7096

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can crea…

Mitigation only
Fix from $1,600 2025-05-30
Api Manager MEDIUM 6.1
CVE-2024-5962

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding o…

Mitigation only
Fix from $1,600 2025-05-22
Identity Server MEDIUM 5.8
CVE-2024-7487

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to …

Mitigation only
Fix from $1,600 2025-05-22
Identity Server MEDIUM 5.4
CVE-2024-7103

A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input va…

Mitigation only
Fix from $1,600 2025-05-22