Skip to main content

Vendor archive

wso2 CVEs

Beta · best-effort

123 CVEs tagged to vendor wso212 Critical, 17 High, 88 Medium, 6 Low, 0 Unrated.

CVE-2025-13475

Published Jul 4, 2026

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific Saa…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2053

Published Jun 26, 2026

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This o…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9973

Published May 11, 2026

Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unint…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10470

Published May 11, 2026

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10908

Published May 11, 2026

Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses th…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10503

Published Apr 29, 2026

The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injecti…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12624

Published Apr 16, 2026

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid t…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6024

Published Apr 16, 2026

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting mali…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8010

Published Apr 16, 2026

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4867

Published Apr 16, 2026

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10242

Published Apr 16, 2026

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1524

Published Feb 24, 2026

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may be replaced…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-12107

Published Feb 19, 2026

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side tem…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10853

Published Nov 5, 2025

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific paramet…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 123 CVEsPage 1 of 5