Api Manager Analytics

WSO2 · 11 CVEs

CVE-2025-9804
HIGH

Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs

Oct 16, 2025

CVE-2023-6911
MEDIUM

Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scriptin…

Dec 18, 2023

CVE-2023-6836
HIGH

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely av…

Dec 15, 2023

CVE-2022-29548
MEDIUM

A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,…

Apr 21, 2022

CVE-2020-17453
MEDIUM

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

Apr 5, 2021

CVE-2020-24706
MEDIUM

An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager throug…

Aug 27, 2020

CVE-2020-24705
HIGH

An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an at…

Aug 27, 2020

CVE-2020-24704
MEDIUM

An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0,…

Aug 27, 2020

CVE-2020-24703
HIGH

An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an at…

Aug 27, 2020

CVE-2020-24591
MEDIUM

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manag…

Aug 21, 2020

CVE-2020-12719
HIGH

XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager…

May 7, 2020

Showing 1 to 11 of 11 CVEs