Skip to main content

Vendor/product archive

wso2 / api_manager CVEs

Beta · best-effort

83 CVEs tagged to wso2 / api_manager12 Critical, 11 High, 58 Medium, 2 Low, 0 Unrated.

CVE-2025-13475

Published Jul 4, 2026

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific Saa…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2053

Published Jun 26, 2026

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This o…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6024

Published Apr 16, 2026

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting mali…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8010

Published Apr 16, 2026

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4867

Published Apr 16, 2026

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10242

Published Apr 16, 2026

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1524

Published Feb 24, 2026

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may be replaced…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-10853

Published Nov 5, 2025

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific paramet…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10907

Published Nov 5, 2025

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious acto…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-5350

Published Oct 24, 2025

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accept…

CVSS 5.9 · Medium
Showing 1-25 of 83 CVEsPage 1 of 4