Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WSO2 | WSO2 Identity Server | 7.0.0 ~ 7.0.0.134 | - | |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 7.0.78 ~ 7.0.78.162 | - | |
| WSO2 | WSO2 Carbon MagicLink Authenticator Module | 1.1.22 ~ 1.1.22.6 | - | |
| WSO2 | WSO2 Carbon Abstract OTP Authenticator | 1.0.5 ~ 1.0.5.4 | - | |
| WSO2 | Email OTP Authenticator | 1.0.30 ~ 1.0.30.4 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5430 | 10.0 CRITICAL | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account |
| CVE-2026-1728 | 9.8 CRITICAL | Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account |
| CVE-2025-15039 | 9.4 CRITICAL | Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products |
| CVE-2024-6832 | 5.9 MEDIUM | Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products |
| CVE-2025-13394 | 5.4 MEDIUM | Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables |
| CVE-2024-8995 | 4.9 MEDIUM | Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthor |
| CVE-2026-0637 | 4.4 MEDIUM | Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products |
| CVE-2025-11850 | 4.3 MEDIUM | Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Ident |
| CVE-2024-10302 | 4.0 MEDIUM | Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Man |
| CVE-2025-14779 | 3.8 LOW | Improper Access Control via Secret Type Management API in WSO2 Identity Server |
| CVE-2025-13736 | 3.7 LOW | Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Dis |
| CVE-2025-12627 | 2.4 LOW | Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server |
No comments yet