19 Total CVEs
19 AI Analyzed
0 CISA KEV
8 Critical

Profile

0% ended up actively exploited 0 of 19 added to CISA KEV
42% rated critical (CVSS 9.0+) 8 critical, 11 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

19 CVEs in the last 12 months

Products

  • WSO2 API Manager2
  • WSO2 Universal Gateway1
  • Universal Gateway, Traffic Manager, API Control Plane, API Manager1
  • API Manager1
  • System REST API1
  • Open Banking AM1

6 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-19 of 19 CVEs
CVE-2026-5430
Analyzed
10
WSO2 WSO2 Universal Gateway

The WSO2 JWT authentication mechanism incorrectly validates tokens using unsupported algorithms, potentially allowing unauthenticated attackers to byp...

2026-08-06
CVE-2026-4249
Analyzed
8.6
WSO2 Universal Gateway, Traffic Manager, API Control Plane, API Manager

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure...

2026-07-07
CVE-2026-3415
Analyzed
8.7
WSO2 WSO2 API Manager

The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows

2026-08-07
CVE-2026-2053
Analyzed
8.3
WSO2 API Manager

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input...

2026-06-26
CVE-2026-1728
Analyzed
9.8
WSO2 WSO2 API Manager

WSO2 API Manager suffers from improper privilege management where low-privileged tokens can access administrative REST APIs, potentially leading to fu...

2026-08-06
CVE-2025-9804
Analyzed
9.6
WSO2 Multiple Products

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Se...

2025-10-16
CVE-2025-9312
Analyzed
9.8
WSO2 Multiple Products

A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multip...

2025-11-19
CVE-2025-9152
Analyzed
9.8
WSO2 Multiple Products

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-ope...

2025-10-16
CVE-2025-6670
Analyzed
8.8
WSO2 Multiple Products

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations...

2025-11-19
CVE-2025-13590
Analyzed
9.1
WSO2 System REST API

A critical flaw in a system REST API allows an authenticated administrator to upload arbitrary files to user-controlled locations, leading to remote c...

2026-02-20
CVE-2025-12737
Analyzed
8.4
WSO2 Open Banking AM

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious act...

2026-09-04
CVE-2025-12107
Analyzed
10
WSO2 Multiple Products

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template...

2026-02-20
CVE-2025-11093
Analyzed
8.4
WSO2 Multiple Products

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediat...

2025-11-06
CVE-2025-10908
Analyzed
7.3
WSO2 Multiple Products

Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass...

2026-05-12
CVE-2025-10907
Analyzed
8.4
WSO2 Multiple Products

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP adm...

2025-11-06
CVE-2025-10611
Analyzed
9.8
WSO2 Multiple Products

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be b...

2025-10-16
CVE-2025-10470
Analyzed
8.6
WSO2 Multiple Products

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to unc...

2026-05-12
CVE-2024-2374
Analyzed
7.5
WSO2 Multiple Products

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entitie...

2026-04-17
CVE-2024-1524
Analyzed
7.7
WSO2 Multiple Products

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's...

2026-02-24