Wso2 carbon api management implementation
This hub aggregates every CVE we track for Wso2 carbon api management implementation, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Cloud & SaaSother
5
CVEs tracked
2
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM2CRITICAL2HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
0
3
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting Wso2 carbon api management implementation.
- CVE-2026-3418Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution9.1
- CVE-2026-3415XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service8.7
- CVE-2025-14561Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations9.0
- CVE-2025-8325Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations6.3
- CVE-2025-8154HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation5.3
Product normalization is registry-driven with AI assist and human review. How it works