CVEs we hold for Wso2
Records whose assigning authority named Wso2 as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-5430Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account TakeoverWSO2 Carbon API Manager Rest API Utility
CVE-2026-4249Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service…WSO2 API Manager
CVE-2026-4103Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script ExecutionWSO2 API Manager
CVE-2026-3418Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code ExecutionWSO2 Carbon API Management API
CVE-2026-3416Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged…WSO2 API Control Plane
CVE-2026-3415XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of…WSO2 Carbon API Management Implementation
CVE-2026-3096Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential TheftWSO2 API Manager
CVE-2026-2445Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and ModificationWSO2 Identity Server
CVE-2026-2053Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API ManagerWSO2 API Manager
CVE-2026-19515OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command ExecutionWSO2 Integrator: MI for Visual Studio Code
CVE-2026-1728Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account TakeoverWSO2 Carbon API Manager Rest API Utility
CVE-2026-0637Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 ProductsWSO2 Carbon Event Publisher Core
CVE-2025-9973Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account TakeoverWSO2 Conditional Authentication User and Roles Related…
CVE-2025-9955Improper Access Control in WSO2 Enterprise Integrator Product via SOAP Admin Services for Logs and User-Store…WSO2 org.wso2.carbon:org.wso2.carbon.server.admin
CVE-2025-9804Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIsWSO2 org.wso2.carbon.identity.workflow.user:org.wso2.carbon.…
CVE-2025-9312Improper Certificate-Based Authentication Enforcement in Multiple WSO2 ProductsWSO2 org.wso2.carbon.identity.auth.service
CVE-2025-9152Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR EndpointWSO2 API Control Plane
CVE-2025-8591Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI ModificationWSO2 Open Banking IAM
CVE-2025-8325Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized OperationsWSO2 Carbon API Manager Rest API Utility
CVE-2025-8154HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header ManipulationWSO2 Carbon API Management Implementation
CVE-2025-6670Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin ServicesWSO2 org.wso2.carbon:org.wso2.carbon.ui
CVE-2025-6508User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information…WSO2 API Manager
CVE-2025-6024Cross-Site Scripting via Authentication Endpoint in Multiple WSO2 Products Allows Redirection to Malicious WebsitesWSO2 Identity Server
CVE-2025-5802Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account DiscoveryWSO2 Carbon Identity Application Authentication Framework
CVE-2025-5770Reflected Cross-Site Scripting (XSS) in Authentication Endpoints of Multiple WSO2 ProductsWSO2 API Control Plane
CVE-2025-5717Authenticated Remote Code Execution in Multiple WSO2 Products via Event Processor Admin ServiceWSO2 Siddhi Extension Evaluate Scripts
CVE-2025-5605Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information…WSO2 org.wso2.carbon:org.wso2.carbon.ui
CVE-2025-5350SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 ProductsWSO2 org.wso2.carbon:org.wso2.carbon.ui
CVE-2025-4760Authenticated Stored Cross-Site Scripting (XSS) in Multiple WSO2 Products via API Document Upload in PublisherWSO2 Carbon API Management API
CVE-2025-3125Authenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Leading to Remote…WSO2 org.wso2.carbon.commons:org.wso2.carbon.application.upl…
CVE-2025-2905An XML External Entity (XXE) vulnerability in Multiple WSO2 ProductsWSO2 Open Banking AM
CVE-2025-1862Authenticated Arbitrary File Upload in Multiple WSO2 Products via BPEL Uploader SOAP Service Leading to Remote Code…WSO2 Identity Server as Key Manager
CVE-2025-15039Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 ProductsWSO2 Carbon Identity Application Authentication Framework
CVE-2025-14779Improper Access Control via Secret Type Management API in WSO2 Identity ServerWSO2 Carbon Identity API Server Secret Management V1
CVE-2025-14561Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant OperationsWSO2 Carbon API Manager Rest API Utility
CVE-2025-1396Username Enumeration in Multiple WSO2 Products with Multi-Attribute Login EnabledWSO2 Identity Server as Key Manager
CVE-2025-13909Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII ExposureWSO2 Email OTP Authenticator
CVE-2025-13736Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account DiscoveryWSO2 Open Banking IAM
CVE-2025-13590Authenticated arbitrary file upload via a System REST API requiring administrator permission.WSO2 org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
CVE-2025-13475Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data ExposureWSO2 API Manager
CVE-2025-13394Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized ActionsWSO2 Carbon Governance
CVE-2025-13166Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account DiscoveryWSO2 Identity Server
CVE-2025-12737Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code ExecutionWSO2 Identity Server
CVE-2025-12627Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued…WSO2 Carbon OAuth
CVE-2025-12624Improper Token Invalidation in WSO2 Identity Server Allows Access After Account LockWSO2 Identity Server
CVE-2025-12317Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access PrivilegesWSO2 Identity Server
CVE-2025-12107Server-Side Template Injection via Velocity Template Engine in Multiple WSO2 Products Allows Remote Code ExecutionWSO2 Identity Server
CVE-2025-11850Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP…WSO2 Token Exchange Grant Type For OAuth
CVE-2025-11093Arbitrary Code Execution with higher privileged users in Multiple WSO2 Products via Script Mediator Engines (GraalJS…WSO2 org.apache.synapse:synapse-extensions
CVE-2025-10908Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized AccessWSO2 Carbon MagicLink Authenticator Module
CVE-2025-10907Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Services Leading to Remote Code ExecutionWSO2 org.wso2.carbon:org.wso2.carbon.utils
CVE-2025-10853Reflected Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products Due to Improper Output EncodingWSO2 org.wso2.carbon.identity.inbound.auth.oauth2:org.wso2.c…
CVE-2025-10713XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser ConfigurationWSO2 org.wso2.carbon.mediation:org.wso2.carbon.localentry
CVE-2025-10611Potential Broken Access Control in Multiple WSO2 Products via System REST APIsWSO2 org.wso2.carbon.identity.auth.rest:org.wso2.carbon.iden…
CVE-2025-10503Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 Identity ServerWSO2 Identity Server
CVE-2025-10470Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service UnavailabilityWSO2 Carbon MagicLink Authenticator Module
CVE-2025-0672Authentication Bypass in Multiple WSO2 Products via Stale FIDO Credential AssociationWSO2 Open Banking IAM
CVE-2025-0663Potential cross-tenant account takeover vulnerability in Multiple WSO2 Products via Adaptive Authentication and…WSO2 Identity Server
CVE-2025-0209Reflected Cross-Site Scripting (XSS) in WSO2 Identity Server Account Registration FlowWSO2 Identity Server
CVE-2024-8995Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized AccessWSO2 Carbon OAuth
CVE-2024-8010XML External Entity Injection via Publisher in WSO2 API Manager Allows Reading Arbitrary FilesWSO2 API Manager
CVE-2024-8008Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection ValidationWSO2 Carbon Identity User Store Configuration UI
CVE-2024-7487Improper Authentication in WSO2 Identity Server 7.0.0 Allows Bypass of App-Native AuthenticationWSO2 Carbon Identity Client Attestation Met Data Mgt BE
CVE-2024-7103Reflected Cross-Site Scripting (XSS) in WSO2 Identity Server 7.0.0 Sub-Organization Login FlowWSO2 Identity Server
CVE-2024-7097Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User SignupWSO2 Enterprise Mobility Manager
CVE-2024-7096Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic FlawWSO2 Open Banking KM
CVE-2024-7074Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Service Leading to Remote Code ExecutionWSO2 Carbon Synapse Artifact Uploader BE
CVE-2024-7073Unauthenticated Server-Side Request Forgery (SSRF) in Multiple WSO2 Products via SOAP Admin ServicesWSO2 Carbon Policy Editor BE
CVE-2024-6914Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account TakeoverWSO2 Carbon Identity Management
CVE-2024-6832Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force AttacksWSO2 Carbon User Manager Kernel
CVE-2024-6541Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 ProductsWSO2 API Manager; WSO2-Synapse
CVE-2024-6429Content Spoofing in Multiple WSO2 Products via Error Message InjectionWSO2 Identity Server
CVE-2024-5962Reflected Cross-Site Scripting (XSS) in Authentication Endpoint of Multiple WSO2 Products Due to Missing Output EncodingWSO2 Identity Server
CVE-2024-5848Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products Due to Improper Input ValidationWSO2 Open Banking AM
CVE-2024-4867Cross-Site Scripting via Developer Portal in WSO2 API Manager Enables UI Modification and Information RetrievalWSO2 API Manager
CVE-2024-4598Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich MediatorWSO2 Micro Integrator
CVE-2024-3511Incorrect Authorization in Multiple WSO2 Products Allows Unauthorized Access to Registry Versioned FilesWSO2 Carbon User Manager Kernel
CVE-2024-3509Stored Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products via Rich Text EditorWSO2 Carbon Registry Resources UI
CVE-2024-2374XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of ServiceWSO2 Identity Server as Key Manager
CVE-2024-2321Incorrect Authorization in Multiple WSO2 Products Allows API Access via Refresh TokenWSO2 Identity Server
CVE-2024-1524A local user can be impersonated when using federated authentication with Silent JIT Provisioning.WSO2 Identity Server
CVE-2024-1440Open Redirection in Multiple WSO2 Products via Multi-Option Authentication EndpointWSO2 Carbon Identity Application Authentication…
CVE-2024-1248Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege EscalationWSO2 Open Banking IAM
CVE-2024-10302Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data ExposureWSO2 Carbon Identity Recovery Management
CVE-2024-10242Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 API Manager Allows UI Modification and RedirectionWSO2 API Manager
CVE-2024-0392Cross-Site Request Forgery (CSRF) in WSO2 Enterprise Integrator 6.6.0 Management Console Due to Missing CSRF Token…WSO2 Enterprise Integrator
CVE-2024-0391Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account DiscoveryWSO2 Carbon Authenticator Library For EmailOTP
CVE-2023-6837Incorrect Authorization in Multiple WSO2 Products via Federated Authentication with JIT Provisioning Leading to User…WSO2 Carbon Identity Application Authentication Framework
CVE-2022-4520WSO2 carbon-registry Advanced Search advancedSearchForm-ajaxprocessor.jsp cross site scriptingWSO2 carbon-registry
95 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.