Api Manager Analytics
WSO2 · 11 CVEs
Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs
Oct 16, 2025
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scriptin…
Dec 18, 2023
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely av…
Dec 15, 2023
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,…
Apr 21, 2022
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Apr 5, 2021
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager throug…
Aug 27, 2020
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an at…
Aug 27, 2020
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0,…
Aug 27, 2020
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an at…
Aug 27, 2020
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manag…
Aug 21, 2020
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager…
May 7, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-9804 | Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs | HIGH | 0.56% | Oct 16, 2025 |
| CVE-2023-6911 | Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an… | MEDIUM | 0.41% | Dec 18, 2023 |
| CVE-2023-6836 | Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML p… | HIGH | 0.48% | Dec 15, 2023 |
| CVE-2022-29548 | A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0;… | MEDIUM | 41.08% | Apr 21, 2022 |
| CVE-2020-17453 | WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. | MEDIUM | 26.22% | Apr 5, 2021 |
| CVE-2020-24706 | An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS… | MEDIUM | 0.79% | Aug 27, 2020 |
| CVE-2020-24705 | An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim s… | HIGH | 1.05% | Aug 27, 2020 |
| CVE-2020-24704 | An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microg… | MEDIUM | 0.72% | Aug 27, 2020 |
| CVE-2020-24703 | An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim s… | HIGH | 1.05% | Aug 27, 2020 |
| CVE-2020-24591 | The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics… | MEDIUM | 1.03% | Aug 21, 2020 |
| CVE-2020-12719 | XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microga… | HIGH | 1.03% | May 7, 2020 |
Showing 1 to 11 of 11 CVEs