VendorsWSO2api_managerall versions
Vulnerabilities

WSO2 API Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2022-29548
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.
Published 2022-04-21 · Modified
6.11 PoCEPSS 0.411
CVE-2020-17453
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Published 2021-04-05 · Modified
6.1EPSS 0.262
CVE-2019-20436
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. If there is a claim dialect configured with an XSS payload in the dialect URI, and a user picks up this dialect's URI and adds it as the service provider claim dialect while configuring the service provider, that payload gets executed. The attacker also needs to have privileges to log in to the management console, and to add and configure claim dialects.
Published 2020-01-27 · Modified
6.1EPSS 0.014
CVE-2019-20437
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a custom claim dialect with an XSS payload is configured in the identity provider basic claim configuration, that payload gets executed, if a user picks up that dialect's URI as the provisioning claim in the advanced claim configuration of the same Identity Provider. The attacker also needs to have privileges to log in to the management console, and to add and update identity provider configurations.
Published 2020-01-27 · Modified
6.1EPSS 0.013
CVE-2023-31664
A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter.
Published 2023-05-23 · Modified
6.1EPSS 0.012
CVE-2020-27885
Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged-in user’s session by stealing cookies which means that a malicious hacker can change the logged-in user’s password and invalidate the session of the victim while the hacker maintains access.
Published 2020-10-29 · Modified
6.1EPSS 0.011
CVE-2020-24706
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
Published 2020-08-27 · Modified
6.1EPSS 0.008
CVE-2020-17454
WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it is possible to inject an XSS payload into the owner POST parameter, which does not filter user inputs. By putting an XSS payload in place of a valid Owner Name, a modal box appears that writes an error message concatenated to the injected payload (without any form of data encoding). This can also be exploited via CSRF.
Published 2020-10-21 · Modified
6.1EPSS 0.008
CVE-2021-36760
In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. (recoverpassword.do also has an open redirect issue for a similar reason.)
Published 2021-12-07 · Modified
6.1EPSS 0.007
CVE-2020-24704
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.
Published 2020-08-27 · Modified
6.1EPSS 0.007
CVE-2023-6838
Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.
Published 2023-12-15 · Modified
6.1EPSS 0.004
CVE-2026-2445
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification
Published 2026-07-20 · Analyzed
6.1EPSS 0.003
CVE-2025-8591
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
Published 2026-07-06 · Analyzed
6.1EPSS 0.003
CVE-2024-5962
Reflected Cross-Site Scripting (XSS) in Authentication Endpoint of Multiple WSO2 Products Due to Missing Output Encoding
Published 2025-05-22 · Analyzed
6.1EPSS 0.003
CVE-2024-10242
Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 API Manager Allows UI Modification and Redirection
Published 2026-04-16 · Analyzed
6.1EPSS 0.002
CVE-2024-5848
Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products Due to Improper Input Validation
Published 2025-02-27 · Analyzed
6.1EPSS 0.002
CVE-2025-6024
Cross-Site Scripting via Authentication Endpoint in Multiple WSO2 Products Allows Redirection to Malicious Websites
Published 2026-04-16 · Analyzed
6.1EPSS 0.002
CVE-2024-1440
Open Redirection in Multiple WSO2 Products via Multi-Option Authentication Endpoint
Published 2025-06-02 · Analyzed
6.1EPSS 0.002
CVE-2025-5770
Reflected Cross-Site Scripting (XSS) in Authentication Endpoints of Multiple WSO2 Products
Published 2025-11-05 · Analyzed
6.1EPSS 0.002
CVE-2025-10853
Reflected Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products Due to Improper Output Encoding
Published 2025-11-05 · Analyzed
6.1EPSS 0.002
CVE-2025-5350
SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products
Published 2025-10-24 · Analyzed
5.9EPSS 0.006
CVE-2024-10302
Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure
Published 2026-08-06 · Undergoing Analysis
5.8EPSS 0.003
CVE-2024-2321
Incorrect Authorization in Multiple WSO2 Products Allows API Access via Refresh Token
Published 2025-02-27 · Analyzed
5.6EPSS 0.002
CVE-2019-6513
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
Published 2019-05-21 · Modified
5.5EPSS 0.013
CVE-2018-20737
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
Published 2019-03-18 · Modified
5.4EPSS 0.010
CVE-2018-20736
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
Published 2019-03-18 · Modified
5.4EPSS 0.010
CVE-2024-7096
Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw
Published 2025-05-30 · Modified
5.4EPSS 0.007
CVE-2024-4867
Cross-Site Scripting via Developer Portal in WSO2 API Manager Enables UI Modification and Information Retrieval
Published 2026-04-16 · Analyzed
5.4EPSS 0.002
CVE-2025-13394
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
Published 2026-08-06 · Analyzed
5.4EPSS 0.001
CVE-2019-6515
An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.
Published 2019-05-14 · Modified
5.3EPSS 0.015
CVE-2025-5605
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
Published 2025-10-24 · Analyzed
5.3EPSS 0.009
CVE-2023-6839
Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.
Published 2023-12-15 · Modified
5.3EPSS 0.005
CVE-2023-6835
Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manipulated.
Published 2023-12-15 · Modified
5.3EPSS 0.005
CVE-2024-1248
Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
Published 2026-07-04 · Analyzed
5.3EPSS 0.003
CVE-2024-8008
Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection Validation
Published 2025-06-02 · Analyzed
5.2EPSS 0.005
CVE-2024-8995
Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
Published 2026-08-06 · Analyzed
4.9EPSS 0.002
CVE-2017-14651
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Published 2017-09-21 · Modified
4.8EPSS 0.038
CVE-2019-20434
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Datasource creation page of the Management Console.
Published 2020-01-27 · Modified
4.8EPSS 0.011
CVE-2019-20435
An issue was discovered in WSO2 API Manager 2.6.0. A reflected XSS attack could be performed in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful docName request parameter.
Published 2020-01-27 · Modified
4.8EPSS 0.011
CVE-2019-20439
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in defining a scope in the "manage the API" page of the API Publisher.
Published 2020-01-27 · Modified
4.8EPSS 0.010
← Prev2 / 3Next →