wso2 records
139 published records for vendor wso2.
Researcher profile
- Entered KEV
- 2 · 1.4%
- Weaponized
- 2 · 1.4%
- Pre-auth RCE
- 3
- With a fix record
- 9.4%
- Median publish → KEV
- 28 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')54
- CWE-611 Improper Restriction of XML External Entity Reference12
- CWE-863 Incorrect Authorization9
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-918 Server-Side Request Forgery (SSRF)5
The weakness classes this vendor ships most often: where to look.
CWEAll records
139 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2022-29464Weaponized | Certain WSO2 products allow unrestricted file upload with resultant remote code execution.wso2 · api manager · CWE-22 | Critical9.8 | KEV | 100.0% | Apr 18, 2022 |
70This week | CVE-2026-5430Weaponized | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeoverwso2 · api control plane · CWE-347 | Critical10.0 | KEV | 0.6% | Aug 6, 2026 |
44Plan | CVE-2020-24589Proof of concept | The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.wso2 · api manager · CWE-611 | Critical9.1 | — | 26.3% | Aug 21, 2020 |
41Plan | CVE-2022-39810No exploit | An issue was discovered in WSO2 Enterprise Integrator 6.4.0.wso2 · enterprise integrator · CWE-79 | Medium6.1 | — | 57.5% | Sep 9, 2022 |
40Plan | CVE-2020-13226No exploit | WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this wso2 · api manager · CWE-918 | Critical9.8 | — | 2.1% | May 20, 2020 |
40Plan | CVE-2026-2053No exploit | Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Managerwso2 · api manager · CWE-918 | Critical10.0 | — | 0.4% | Jun 26, 2026 |
39Monitor | CVE-2025-10611No exploit | Potential Broken Access Control in Multiple WSO2 Products via System REST APIswso2 · api control plane · CWE-863 | Critical9.8 | — | 0.8% | Oct 16, 2025 |
39Monitor | CVE-2024-6914No exploit | Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeoverwso2 · api manager · CWE-863 | Critical9.8 | — | 0.7% | May 22, 2025 |
39Monitor | CVE-2025-9152No exploit | Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpointwso2 · api control plane · CWE-306 | Critical9.8 | — | 0.7% | Oct 16, 2025 |
39Monitor | CVE-2026-1728No exploit | Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeoverwso2 · api control plane · CWE-269 | Critical9.8 | — | 0.5% | Aug 6, 2026 |
39Monitor | CVE-2025-9312No exploit | Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Productswso2 · api control plane · CWE-306 | Critical9.8 | — | 0.2% | Nov 18, 2025 |
37Monitor | CVE-2021-42646No exploit | XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.wso2 · api manager · CWE-611 | Critical9.1 | — | 3.7% | May 11, 2022 |
37Monitor | CVE-2025-15039No exploit | Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Productswso2 · api control plane · CWE-693 | Critical9.4 | — | 0.7% | Aug 6, 2026 |
36Monitor | CVE-2022-29548Proof of concept | A reflected XSS issue exists in the Management Console of several WSO2 products.wso2 · api manager · CWE-79 | Medium6.1 | — | 41.1% | Apr 20, 2022 |
36Monitor | CVE-2016-4311Proof of concept | Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack thwso2 · identity server · CWE-352 | High8.8 | — | 3.4% | Feb 16, 2017 |
36Monitor | CVE-2025-2905No exploit | An XML External Entity (XXE) vulnerability in Multiple WSO2 Productswso2 · api manager · CWE-611 | Critical9.1 | — | 1.3% | May 5, 2025 |
36Monitor | CVE-2020-24590No exploit | The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.wso2 · api manager · CWE-776 | Critical9.1 | — | 1.3% | Aug 21, 2020 |
36Monitor | CVE-2025-10713No exploit | XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configurationwso2 · api control plane · CWE-611 | Critical9.1 | — | 0.4% | Nov 5, 2025 |
36Monitor | CVE-2024-2374No exploit | XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Servicewso2 · api manager · CWE-611 | Critical9.1 | — | 0.4% | Apr 16, 2026 |
35Monitor | CVE-2020-24703No exploit | An issue was discovered in certain WSO2 products.wso2 · api manager | High8.8 | — | 1.1% | Aug 27, 2020 |
35Monitor | CVE-2020-24705No exploit | An issue was discovered in certain WSO2 products.wso2 · api manager | High8.8 | — | 1.1% | Aug 27, 2020 |
35Monitor | CVE-2025-6670No exploit | Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Serviceswso2 · api control plane · CWE-352 | High8.8 | — | 0.2% | Nov 18, 2025 |
35Monitor | CVE-2025-8325No exploit | Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operationswso2 · api control plane · CWE-281 | High8.8 | — | 0.2% | May 11, 2026 |
34Monitor | CVE-2026-4249No exploit | Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruptionwso2 · api control plane · CWE-707 | High8.6 | — | 0.6% | Jul 6, 2026 |
34Monitor | CVE-2025-10470No exploit | Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailabilitywso2 · identity server · CWE-400 | High8.6 | — | 0.3% | May 11, 2026 |
- CVE-2022-2946499Now
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%wso2 · api managerApr 18, 2022
- CVE-2026-543070This week
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
CriticalCVSS 10.0KEVWeaponizedEPSS 1%wso2 · api control planeAug 6, 2026
- CVE-2020-2458944Plan
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
CriticalCVSS 9.1Proof of conceptEPSS 26%wso2 · api managerAug 21, 2020
- CVE-2022-3981041Plan
An issue was discovered in WSO2 Enterprise Integrator 6.4.0.
MediumCVSS 6.1No exploitEPSS 57%wso2 · enterprise integratorSep 9, 2022
- CVE-2020-1322640Plan
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this
CriticalCVSS 9.8No exploitEPSS 2%wso2 · api managerMay 20, 2020
- CVE-2026-205340Plan
Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
CriticalCVSS 10.0No exploitEPSS 0%wso2 · api managerJun 26, 2026
- CVE-2025-1061139Monitor
Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
CriticalCVSS 9.8No exploitEPSS 1%wso2 · api control planeOct 16, 2025
- CVE-2024-691439Monitor
Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeover
CriticalCVSS 9.8No exploitEPSS 1%wso2 · api managerMay 22, 2025
- CVE-2025-915239Monitor
Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint
CriticalCVSS 9.8No exploitEPSS 1%wso2 · api control planeOct 16, 2025
- CVE-2026-172839Monitor
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
CriticalCVSS 9.8No exploitEPSS 0%wso2 · api control planeAug 6, 2026
- CVE-2025-931239Monitor
Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products
CriticalCVSS 9.8No exploitEPSS 0%wso2 · api control planeNov 18, 2025
- CVE-2021-4264637Monitor
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.
CriticalCVSS 9.1No exploitEPSS 4%wso2 · api managerMay 11, 2022
- CVE-2025-1503937Monitor
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
CriticalCVSS 9.4No exploitEPSS 1%wso2 · api control planeAug 6, 2026
- CVE-2022-2954836Monitor
A reflected XSS issue exists in the Management Console of several WSO2 products.
MediumCVSS 6.1Proof of conceptEPSS 41%wso2 · api managerApr 20, 2022
- CVE-2016-431136Monitor
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack th
HighCVSS 8.8Proof of conceptEPSS 3%wso2 · identity serverFeb 16, 2017
- CVE-2025-290536Monitor
An XML External Entity (XXE) vulnerability in Multiple WSO2 Products
CriticalCVSS 9.1No exploitEPSS 1%wso2 · api managerMay 5, 2025
- CVE-2020-2459036Monitor
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
CriticalCVSS 9.1No exploitEPSS 1%wso2 · api managerAug 21, 2020
- CVE-2025-1071336Monitor
XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configuration
CriticalCVSS 9.1No exploitEPSS 0%wso2 · api control planeNov 5, 2025
- CVE-2024-237436Monitor
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service
CriticalCVSS 9.1No exploitEPSS 0%wso2 · api managerApr 16, 2026
- CVE-2020-2470335Monitor
An issue was discovered in certain WSO2 products.
HighCVSS 8.8No exploitEPSS 1%wso2 · api managerAug 27, 2020
- CVE-2020-2470535Monitor
An issue was discovered in certain WSO2 products.
HighCVSS 8.8No exploitEPSS 1%wso2 · api managerAug 27, 2020
- CVE-2025-667035Monitor
Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services
HighCVSS 8.8No exploitEPSS 0%wso2 · api control planeNov 18, 2025
- CVE-2025-832535Monitor
Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations
HighCVSS 8.8No exploitEPSS 0%wso2 · api control planeMay 11, 2026
- CVE-2026-424934Monitor
Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
HighCVSS 8.6No exploitEPSS 1%wso2 · api control planeJul 6, 2026
- CVE-2025-1047034Monitor
Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability
HighCVSS 8.6No exploitEPSS 0%wso2 · identity serverMay 11, 2026