Skip to main content

Vendor/product archive

wso2 / traffic_manager CVEs

Beta · best-effort

18 CVEs tagged to wso2 / traffic_manager4 Critical, 4 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2025-10853

Published Nov 5, 2025

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific paramet…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10907

Published Nov 5, 2025

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious acto…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-5350

Published Oct 24, 2025

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accept…

CVSS 5.9 · Medium

CVE-2025-10611

Published Oct 16, 2025

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Showing 1-18 of 18 CVEsPage 1 of 1