wso2 kayıtları
wso2 üreticisine ait 139 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %1,4
- Silahlaştırılmış
- 2 · %1,4
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %9,4
- Yayından KEV’e ortanca
- 28 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')54
- CWE-611 Improper Restriction of XML External Entity Reference12
- CWE-863 Incorrect Authorization9
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-918 Server-Side Request Forgery (SSRF)5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
139 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2022-29464Silahlaştırılmış | Certain WSO2 products allow unrestricted file upload with resultant remote code execution.wso2 · api manager · CWE-22 | Kritik9,8 | KEV | %100,0 | 18 Nis 2022 |
70Bu hafta | CVE-2026-5430Silahlaştırılmış | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeoverwso2 · api control plane · CWE-347 | Kritik10,0 | KEV | %0,6 | 6 Ağu 2026 |
44Planlayın | CVE-2020-24589Kavram kanıtı | The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.wso2 · api manager · CWE-611 | Kritik9,1 | — | %26,3 | 21 Ağu 2020 |
41Planlayın | CVE-2022-39810İstismar yok | An issue was discovered in WSO2 Enterprise Integrator 6.4.0.wso2 · enterprise integrator · CWE-79 | Orta6,1 | — | %57,5 | 9 Eyl 2022 |
40Planlayın | CVE-2020-13226İstismar yok | WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this wso2 · api manager · CWE-918 | Kritik9,8 | — | %2,1 | 20 May 2020 |
40Planlayın | CVE-2026-2053İstismar yok | Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Managerwso2 · api manager · CWE-918 | Kritik10,0 | — | %0,4 | 26 Haz 2026 |
39İzleyin | CVE-2025-10611İstismar yok | Potential Broken Access Control in Multiple WSO2 Products via System REST APIswso2 · api control plane · CWE-863 | Kritik9,8 | — | %0,8 | 16 Eki 2025 |
39İzleyin | CVE-2024-6914İstismar yok | Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeoverwso2 · api manager · CWE-863 | Kritik9,8 | — | %0,7 | 22 May 2025 |
39İzleyin | CVE-2025-9152İstismar yok | Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpointwso2 · api control plane · CWE-306 | Kritik9,8 | — | %0,7 | 16 Eki 2025 |
39İzleyin | CVE-2026-1728İstismar yok | Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeoverwso2 · api control plane · CWE-269 | Kritik9,8 | — | %0,5 | 6 Ağu 2026 |
39İzleyin | CVE-2025-9312İstismar yok | Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Productswso2 · api control plane · CWE-306 | Kritik9,8 | — | %0,2 | 18 Kas 2025 |
37İzleyin | CVE-2021-42646İstismar yok | XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.wso2 · api manager · CWE-611 | Kritik9,1 | — | %3,7 | 11 May 2022 |
37İzleyin | CVE-2025-15039İstismar yok | Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Productswso2 · api control plane · CWE-693 | Kritik9,4 | — | %0,7 | 6 Ağu 2026 |
36İzleyin | CVE-2022-29548Kavram kanıtı | A reflected XSS issue exists in the Management Console of several WSO2 products.wso2 · api manager · CWE-79 | Orta6,1 | — | %41,1 | 20 Nis 2022 |
36İzleyin | CVE-2016-4311Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack thwso2 · identity server · CWE-352 | Yüksek8,8 | — | %3,4 | 16 Şub 2017 |
36İzleyin | CVE-2025-2905İstismar yok | An XML External Entity (XXE) vulnerability in Multiple WSO2 Productswso2 · api manager · CWE-611 | Kritik9,1 | — | %1,3 | 5 May 2025 |
36İzleyin | CVE-2020-24590İstismar yok | The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.wso2 · api manager · CWE-776 | Kritik9,1 | — | %1,3 | 21 Ağu 2020 |
36İzleyin | CVE-2025-10713İstismar yok | XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configurationwso2 · api control plane · CWE-611 | Kritik9,1 | — | %0,4 | 5 Kas 2025 |
36İzleyin | CVE-2024-2374İstismar yok | XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Servicewso2 · api manager · CWE-611 | Kritik9,1 | — | %0,4 | 16 Nis 2026 |
35İzleyin | CVE-2020-24703İstismar yok | An issue was discovered in certain WSO2 products.wso2 · api manager | Yüksek8,8 | — | %1,1 | 27 Ağu 2020 |
35İzleyin | CVE-2020-24705İstismar yok | An issue was discovered in certain WSO2 products.wso2 · api manager | Yüksek8,8 | — | %1,1 | 27 Ağu 2020 |
35İzleyin | CVE-2025-6670İstismar yok | Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Serviceswso2 · api control plane · CWE-352 | Yüksek8,8 | — | %0,2 | 18 Kas 2025 |
35İzleyin | CVE-2025-8325İstismar yok | Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operationswso2 · api control plane · CWE-281 | Yüksek8,8 | — | %0,2 | 11 May 2026 |
34İzleyin | CVE-2026-4249İstismar yok | Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruptionwso2 · api control plane · CWE-707 | Yüksek8,6 | — | %0,6 | 6 Tem 2026 |
34İzleyin | CVE-2025-10470İstismar yok | Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailabilitywso2 · identity server · CWE-400 | Yüksek8,6 | — | %0,3 | 11 May 2026 |
- CVE-2022-2946499Hemen
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100wso2 · api manager18 Nis 2022
- CVE-2026-543070Bu hafta
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %1wso2 · api control plane6 Ağu 2026
- CVE-2020-2458944Planlayın
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
KritikCVSS 9,1Kavram kanıtıEPSS %26wso2 · api manager21 Ağu 2020
- CVE-2022-3981041Planlayın
An issue was discovered in WSO2 Enterprise Integrator 6.4.0.
OrtaCVSS 6,1İstismar yokEPSS %57wso2 · enterprise integrator9 Eyl 2022
- CVE-2020-1322640Planlayın
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this
KritikCVSS 9,8İstismar yokEPSS %2wso2 · api manager20 May 2020
- CVE-2026-205340Planlayın
Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
KritikCVSS 10,0İstismar yokEPSS %0wso2 · api manager26 Haz 2026
- CVE-2025-1061139İzleyin
Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
KritikCVSS 9,8İstismar yokEPSS %1wso2 · api control plane16 Eki 2025
- CVE-2024-691439İzleyin
Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeover
KritikCVSS 9,8İstismar yokEPSS %1wso2 · api manager22 May 2025
- CVE-2025-915239İzleyin
Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint
KritikCVSS 9,8İstismar yokEPSS %1wso2 · api control plane16 Eki 2025
- CVE-2026-172839İzleyin
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
KritikCVSS 9,8İstismar yokEPSS %0wso2 · api control plane6 Ağu 2026
- CVE-2025-931239İzleyin
Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products
KritikCVSS 9,8İstismar yokEPSS %0wso2 · api control plane18 Kas 2025
- CVE-2021-4264637İzleyin
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.
KritikCVSS 9,1İstismar yokEPSS %4wso2 · api manager11 May 2022
- CVE-2025-1503937İzleyin
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
KritikCVSS 9,4İstismar yokEPSS %1wso2 · api control plane6 Ağu 2026
- CVE-2022-2954836İzleyin
A reflected XSS issue exists in the Management Console of several WSO2 products.
OrtaCVSS 6,1Kavram kanıtıEPSS %41wso2 · api manager20 Nis 2022
- CVE-2016-431136İzleyin
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack th
YüksekCVSS 8,8Kavram kanıtıEPSS %3wso2 · identity server16 Şub 2017
- CVE-2025-290536İzleyin
An XML External Entity (XXE) vulnerability in Multiple WSO2 Products
KritikCVSS 9,1İstismar yokEPSS %1wso2 · api manager5 May 2025
- CVE-2020-2459036İzleyin
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
KritikCVSS 9,1İstismar yokEPSS %1wso2 · api manager21 Ağu 2020
- CVE-2025-1071336İzleyin
XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configuration
KritikCVSS 9,1İstismar yokEPSS %0wso2 · api control plane5 Kas 2025
- CVE-2024-237436İzleyin
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service
KritikCVSS 9,1İstismar yokEPSS %0wso2 · api manager16 Nis 2026
- CVE-2020-2470335İzleyin
An issue was discovered in certain WSO2 products.
YüksekCVSS 8,8İstismar yokEPSS %1wso2 · api manager27 Ağu 2020
- CVE-2020-2470535İzleyin
An issue was discovered in certain WSO2 products.
YüksekCVSS 8,8İstismar yokEPSS %1wso2 · api manager27 Ağu 2020
- CVE-2025-667035İzleyin
Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services
YüksekCVSS 8,8İstismar yokEPSS %0wso2 · api control plane18 Kas 2025
- CVE-2025-832535İzleyin
Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations
YüksekCVSS 8,8İstismar yokEPSS %0wso2 · api control plane11 May 2026
- CVE-2026-424934İzleyin
Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
YüksekCVSS 8,6İstismar yokEPSS %1wso2 · api control plane6 Tem 2026
- CVE-2025-1047034İzleyin
Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability
YüksekCVSS 8,6İstismar yokEPSS %0wso2 · identity server11 May 2026