wso2
Latest CVEs
The 15 most recently published vulnerabilities affecting wso2.
- CVE-2026-3418Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution9.1
- CVE-2026-3415XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service8.7
- CVE-2025-14561Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations9.0
- CVE-2025-12317Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges5.0
- CVE-2025-6508User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information Exposure or Unintended Requests4.3
- CVE-2024-6541Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products6.8
- CVE-2026-5430Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover10.0
- CVE-2026-1728Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover9.8
- CVE-2025-15039Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products9.4
- CVE-2026-0637Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products4.4
- CVE-2025-13394Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions5.4
- CVE-2025-13909Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure4.3
- CVE-2025-12627Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions2.4
- CVE-2025-14779Improper Access Control via Secret Type Management API in WSO2 Identity Server3.8
- CVE-2025-11850Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use]4.3