Skip to main content

Vendor/product archive

wso2 / open_banking_km CVEs

Beta · best-effort

8 CVEs tagged to wso2 / open_banking_km5 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-10611

Published Oct 16, 2025

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-29464

Published Apr 18, 2022

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traver…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
68.4
KEV listedPublic PoC observed
Showing 1-8 of 8 CVEsPage 1 of 1