Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WSO2 — Vulnerabilities & Security Advisories 88

Browse all 88 CVE security advisories affecting WSO2. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WSO2 provides an open-source platform for API management, identity and access management, and enterprise integration. Its middleware architecture, which facilitates complex digital transformations, has historically been a target for attackers due to its broad attack surface. The 57 recorded Common Vulnerabilities and Exposures (CVEs) predominantly involve remote code execution, cross-site scripting, and authentication bypass flaws. These issues often stem from improper input validation and insecure default configurations within its API gateway and identity server components. While no single catastrophic breach has defined the vendor’s public history, the high volume of vulnerabilities indicates systemic weaknesses in code review processes for legacy modules. Security practitioners must prioritize patching these known exploits, particularly those affecting exposed management consoles, to prevent unauthorized access and data exfiltration in enterprise environments relying on this integration suite.

CVE IDTitleCVSSSeverityPublished
CVE-2026-3418 Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution — WSO2 API ManagerCWE-434 9.1 Critical2026-08-06
CVE-2026-3415 XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service — WSO2 API ManagerCWE-776 8.7 High2026-08-06
CVE-2025-14561 Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations — WSO2 API ManagerCWE-284 9.0 Critical2026-08-06
CVE-2025-12317 Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges — WSO2 Enterprise IntegratorCWE-613 5.0 Medium2026-08-06
CVE-2025-6508 User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information Exposure or Unintended Requests — WSO2 API ManagerCWE-79 4.3 Medium2026-08-06
CVE-2024-6541 Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products — WSO2 Micro IntegratorCWE-20 6.8 Medium2026-08-06
CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover — WSO2 Universal GatewayCWE-347 10.0 Critical2026-08-06
CVE-2026-1728 Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover — WSO2 API ManagerCWE-269 9.8 Critical2026-08-06
CVE-2025-15039 Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products — WSO2 Identity ServerCWE-693 9.4 Critical2026-08-06
CVE-2026-0637 Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products — WSO2 API ManagerCWE-532 4.4 Medium2026-08-06
CVE-2025-13394 Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions — WSO2 Identity ServerCWE-352 5.4 Medium2026-08-06
CVE-2025-13909 Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure — WSO2 Identity ServerCWE-200 4.3 Medium2026-08-06
CVE-2025-12627 Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions — WSO2 Identity ServerCWE-613 2.4 Low2026-08-06
CVE-2025-14779 Improper Access Control via Secret Type Management API in WSO2 Identity Server — WSO2 Identity ServerCWE-281 3.8 Low2026-08-06
CVE-2025-11850 Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use] — WSO2 Identity Server 4.3 Medium2026-08-06
CVE-2025-13736 Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery — WSO2 Identity Server as Key ManagerCWE-203 3.7 Low2026-08-06
CVE-2024-10302 Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure — WSO2 API Control PlaneCWE-20 4.0 Medium2026-08-06
CVE-2024-6832 Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks — WSO2 Enterprise IntegratorCWE-693 5.9 Medium2026-08-06
CVE-2024-8995 Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access — WSO2 API ManagerCWE-613 4.9 Medium2026-08-06
CVE-2026-2445 Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification — WSO2 API ManagerCWE-79 6.1 Medium2026-07-20
CVE-2026-4249 Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption — WSO2 Universal GatewayCWE-707 8.6 High2026-07-06
CVE-2025-8591 Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification — WSO2 Identity ServerCWE-79 6.1 Medium2026-07-06
CVE-2024-1248 Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation — WSO2 API ManagerCWE-298 4.8 Medium2026-07-04
CVE-2025-13475 Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure — WSO2 Identity ServerCWE-288 3.5 Low2026-07-04
CVE-2026-2053 Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager — WSO2 API ManagerCWE-918 8.3 High2026-06-26
CVE-2025-10470 Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability — WSO2 Identity ServerCWE-400 8.6 High2026-05-11
CVE-2025-9973 Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover — WSO2 Identity Server 6.4 Medium2026-05-11
CVE-2025-8325 Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations — WSO2 API Control PlaneCWE-281 6.3 Medium2026-05-11
CVE-2025-8154 HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation — WSO2 API ManagerCWE-74 5.3 Medium2026-05-11
CVE-2025-10908 Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized Access — WSO2 Identity ServerCWE-863--2026-05-11

This page lists every published CVE security advisory associated with WSO2. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.