WSO2 / Api Manager
95 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-12737 | Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution | HIGH | 8.4 | Sep 3, 2026 |
| CVE-2026-3416 | Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads | HIGH | 7.5 | Sep 3, 2026 |
| CVE-2026-5430 KEV | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover | CRITICAL | 10.0 | Aug 6, 2026 |
| CVE-2026-1728 | Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover | CRITICAL | 9.8 | Aug 6, 2026 |
| CVE-2025-15039 | Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products | CRITICAL | 9.4 | Aug 6, 2026 |
| CVE-2026-0637 | Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products | MEDIUM | 4.4 | Aug 6, 2026 |
| CVE-2025-13394 | Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions | MEDIUM | 5.4 | Aug 6, 2026 |
| CVE-2025-13736 | Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery | LOW | 3.7 | Aug 6, 2026 |
| CVE-2024-10302 | Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure | MEDIUM | 5.8 | Aug 6, 2026 |
| CVE-2024-6832 | Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks | HIGH | 7.5 | Aug 6, 2026 |
| CVE-2024-8995 | Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access | MEDIUM | 4.9 | Aug 6, 2026 |
| CVE-2026-2445 | Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification | MEDIUM | 6.1 | Jul 20, 2026 |
| CVE-2026-4249 | Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption | HIGH | 8.6 | Jul 6, 2026 |
| CVE-2025-8591 | Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification | MEDIUM | 6.1 | Jul 6, 2026 |
| CVE-2024-1248 | Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation | MEDIUM | 5.3 | Jul 4, 2026 |
| CVE-2025-13475 | Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure | HIGH | 7.3 | Jul 4, 2026 |
| CVE-2026-2053 | Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager | CRITICAL | 10.0 | Jun 26, 2026 |
| CVE-2025-8325 | Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations | HIGH | 8.8 | May 11, 2026 |
| CVE-2025-8154 | HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation | HIGH | 7.5 | May 11, 2026 |
| CVE-2025-6024 | Cross-Site Scripting via Authentication Endpoint in Multiple WSO2 Products Allows Redirection to Malicious Websites | MEDIUM | 6.1 | Apr 16, 2026 |
| CVE-2024-10242 | Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 API Manager Allows UI Modification and Redirection | MEDIUM | 6.1 | Apr 16, 2026 |
| CVE-2024-8010 | XML External Entity Injection via Publisher in WSO2 API Manager Allows Reading Arbitrary Files | HIGH | 7.5 | Apr 16, 2026 |
| CVE-2024-4867 | Cross-Site Scripting via Developer Portal in WSO2 API Manager Enables UI Modification and Information Retrieval | MEDIUM | 5.4 | Apr 16, 2026 |
| CVE-2024-2374 | XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service | CRITICAL | 9.1 | Apr 16, 2026 |
| CVE-2024-1524 | A local user can be impersonated when using federated authentication with Silent JIT Provisioning. | HIGH | 8.1 | Feb 24, 2026 |
Showing 1 to 25 of 95 CVEs