İçeriğe atla
Noroxi

wso2 kayıtları

wso2 üreticisine ait 139 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
2 · %1,4
Silahlaştırılmış
2 · %1,4
Pre-auth RCE
3
Düzeltme kaydı olan
%9,4
Yayından KEV’e ortanca
28 gün

Tüm kayıtlar

139 kayıt
  • Certain WSO2 products allow unrestricted file upload with resultant remote code execution.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    wso2 · api manager18 Nis 2022

  • CVE-2026-5430
    70Bu hafta

    Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %1

    wso2 · api control plane6 Ağu 2026

  • CVE-2020-24589
    44Planlayın

    The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

    KritikCVSS 9,1Kavram kanıtıEPSS %26

    wso2 · api manager21 Ağu 2020

  • CVE-2022-39810
    41Planlayın

    An issue was discovered in WSO2 Enterprise Integrator 6.4.0.

    OrtaCVSS 6,1İstismar yokEPSS %57

    wso2 · enterprise integrator9 Eyl 2022

  • CVE-2020-13226
    40Planlayın

    WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this

    KritikCVSS 9,8İstismar yokEPSS %2

    wso2 · api manager20 May 2020

  • CVE-2026-2053
    40Planlayın

    Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager

    KritikCVSS 10,0İstismar yokEPSS %0

    wso2 · api manager26 Haz 2026

  • CVE-2025-10611
    39İzleyin

    Potential Broken Access Control in Multiple WSO2 Products via System REST APIs

    KritikCVSS 9,8İstismar yokEPSS %1

    wso2 · api control plane16 Eki 2025

  • CVE-2024-6914
    39İzleyin

    Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeover

    KritikCVSS 9,8İstismar yokEPSS %1

    wso2 · api manager22 May 2025

  • CVE-2025-9152
    39İzleyin

    Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint

    KritikCVSS 9,8İstismar yokEPSS %1

    wso2 · api control plane16 Eki 2025

  • CVE-2026-1728
    39İzleyin

    Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover

    KritikCVSS 9,8İstismar yokEPSS %0

    wso2 · api control plane6 Ağu 2026

  • CVE-2025-9312
    39İzleyin

    Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products

    KritikCVSS 9,8İstismar yokEPSS %0

    wso2 · api control plane18 Kas 2025

  • CVE-2021-42646
    37İzleyin

    XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.

    KritikCVSS 9,1İstismar yokEPSS %4

    wso2 · api manager11 May 2022

  • CVE-2025-15039
    37İzleyin

    Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products

    KritikCVSS 9,4İstismar yokEPSS %1

    wso2 · api control plane6 Ağu 2026

  • CVE-2022-29548
    36İzleyin

    A reflected XSS issue exists in the Management Console of several WSO2 products.

    OrtaCVSS 6,1Kavram kanıtıEPSS %41

    wso2 · api manager20 Nis 2022

  • CVE-2016-4311
    36İzleyin

    Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack th

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    wso2 · identity server16 Şub 2017

  • CVE-2025-2905
    36İzleyin

    An XML External Entity (XXE) vulnerability in Multiple WSO2 Products

    KritikCVSS 9,1İstismar yokEPSS %1

    wso2 · api manager5 May 2025

  • CVE-2020-24590
    36İzleyin

    The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.

    KritikCVSS 9,1İstismar yokEPSS %1

    wso2 · api manager21 Ağu 2020

  • CVE-2025-10713
    36İzleyin

    XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configuration

    KritikCVSS 9,1İstismar yokEPSS %0

    wso2 · api control plane5 Kas 2025

  • CVE-2024-2374
    36İzleyin

    XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service

    KritikCVSS 9,1İstismar yokEPSS %0

    wso2 · api manager16 Nis 2026

  • CVE-2020-24703
    35İzleyin

    An issue was discovered in certain WSO2 products.

    YüksekCVSS 8,8İstismar yokEPSS %1

    wso2 · api manager27 Ağu 2020

  • CVE-2020-24705
    35İzleyin

    An issue was discovered in certain WSO2 products.

    YüksekCVSS 8,8İstismar yokEPSS %1

    wso2 · api manager27 Ağu 2020

  • CVE-2025-6670
    35İzleyin

    Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services

    YüksekCVSS 8,8İstismar yokEPSS %0

    wso2 · api control plane18 Kas 2025

  • CVE-2025-8325
    35İzleyin

    Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations

    YüksekCVSS 8,8İstismar yokEPSS %0

    wso2 · api control plane11 May 2026

  • CVE-2026-4249
    34İzleyin

    Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption

    YüksekCVSS 8,6İstismar yokEPSS %1

    wso2 · api control plane6 Tem 2026

  • CVE-2025-10470
    34İzleyin

    Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability

    YüksekCVSS 8,6İstismar yokEPSS %0

    wso2 · identity server11 May 2026