VendorsWSO2api_managerall versions
Vulnerabilities

WSO2 API Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Published 2022-04-18 · Analyzed
10.0KEVEPSS 1.000
CVE-2026-2053
Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
Published 2026-06-26 · Analyzed
10.0EPSS 0.004
CVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Published 2026-08-06 · Modified
10.0KEVEPSS 0.004
CVE-2020-13226
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
Published 2020-05-20 · Modified
9.8EPSS 0.021
CVE-2025-10611
Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
Published 2025-10-16 · Analyzed
9.8EPSS 0.008
CVE-2024-6914
Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeover
Published 2025-05-22 · Analyzed
9.8EPSS 0.007
CVE-2025-9152
Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint
Published 2025-10-16 · Analyzed
9.8EPSS 0.007
CVE-2026-1728
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
Published 2026-08-06 · Analyzed
9.8EPSS 0.005
CVE-2025-9312
Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products
Published 2025-11-18 · Analyzed
9.8EPSS 0.002
CVE-2025-9804
Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs
Published 2025-10-16 · Analyzed
9.6EPSS 0.006
CVE-2025-15039
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
9.4EPSS 0.007
CVE-2020-24589
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Published 2020-08-21 · Modified
9.1EPSS 0.263
CVE-2021-42646
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.
Published 2022-05-11 · Modified
9.1EPSS 0.037
CVE-2025-2905
An XML External Entity (XXE) vulnerability in Multiple WSO2 Products
Published 2025-05-05 · Modified
9.1EPSS 0.013
CVE-2020-24590
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Published 2020-08-21 · Modified
9.1EPSS 0.013
CVE-2025-13590
Authenticated arbitrary file upload via a System REST API requiring administrator permission.
Published 2026-02-19 · Modified
9.1EPSS 0.007
CVE-2025-10713
XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Configuration
Published 2025-11-05 · Analyzed
9.1EPSS 0.004
CVE-2024-2374
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service
Published 2026-04-16 · Analyzed
9.1EPSS 0.004
CVE-2020-24703
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.
Published 2020-08-27 · Modified
8.8EPSS 0.011
CVE-2020-24705
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
Published 2020-08-27 · Modified
8.8EPSS 0.011
CVE-2025-6670
Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services
Published 2025-11-18 · Analyzed
8.8EPSS 0.002
CVE-2025-8325
Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations
Published 2026-05-11 · Analyzed
8.8EPSS 0.002
CVE-2020-12719
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.
Published 2020-05-07 · Modified
8.7EPSS 0.010
CVE-2026-4249
Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
Published 2026-07-06 · Analyzed
8.6EPSS 0.006
CVE-2023-6837
Incorrect Authorization in Multiple WSO2 Products via Federated Authentication with JIT Provisioning Leading to User Impersonation
Published 2023-12-15 · Modified
8.5EPSS 0.005
CVE-2025-10907
Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Services Leading to Remote Code Execution
Published 2025-11-05 · Analyzed
8.4EPSS 0.006
CVE-2025-11093
Arbitrary Code Execution with higher privileged users in Multiple WSO2 Products via Script Mediator Engines (GraalJS and NashornJS)
Published 2025-11-05 · Analyzed
8.4EPSS 0.004
CVE-2025-12737
Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution
Published 2026-09-03 · Analyzed
8.4EPSS 0.002
CVE-2024-1524
A local user can be impersonated when using federated authentication with Silent JIT Provisioning.
Published 2026-02-24 · Analyzed
8.1EPSS 0.003
CVE-2023-6836
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
Published 2023-12-15 · Modified
7.5EPSS 0.005
CVE-2024-6832
Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks
Published 2026-08-06 · Analyzed
7.5EPSS 0.004
CVE-2026-3416
Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads
Published 2026-09-03 · Analyzed
7.5EPSS 0.004
CVE-2024-8010
XML External Entity Injection via Publisher in WSO2 API Manager Allows Reading Arbitrary Files
Published 2026-04-16 · Analyzed
7.5EPSS 0.003
CVE-2025-8154
HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation
Published 2026-05-11 · Analyzed
7.5EPSS 0.002
CVE-2025-13475
Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure
Published 2026-07-04 · Analyzed
7.3EPSS 0.003
CVE-2025-3125
Authenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Leading to Remote Code Execution
Published 2025-11-05 · Analyzed
7.2EPSS 0.008
CVE-2025-5717
Authenticated Remote Code Execution in Multiple WSO2 Products via Event Processor Admin Service
Published 2025-09-23 · Analyzed
7.2EPSS 0.007
CVE-2020-13883
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
Published 2020-06-06 · Modified
6.7EPSS 0.008
CVE-2020-24591
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.
Published 2020-08-21 · Modified
6.5EPSS 0.010
CVE-2024-4598
Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediator
Published 2025-09-23 · Analyzed
6.5EPSS 0.003
1 / 3Next →