Skip to main content

Vendor/product archive

wso2 / identity_server_as_key_manager CVEs

Beta · best-effort

51 CVEs tagged to wso2 / identity_server_as_key_manager7 Critical, 7 High, 34 Medium, 3 Low, 0 Unrated.

CVE-2026-0637

Published Aug 6, 2026

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or s…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-15039

Published Aug 6, 2026

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern i…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-13394

Published Aug 6, 2026

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HT…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-8995

Published Aug 6, 2026

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-6832

Published Aug 6, 2026

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reac…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10853

Published Nov 5, 2025

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific paramet…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10907

Published Nov 5, 2025

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious acto…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-3125

Published Nov 5, 2025

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-5605

Published Oct 24, 2025

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to b…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-5350

Published Oct 24, 2025

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accept…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10611

Published Oct 16, 2025

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 51 CVEsPage 1 of 3