VendorsWSO2api_managerall versions
Vulnerabilities

WSO2 API Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2019-20441
An issue was discovered in WSO2 API Manager 2.6.0. A potential Stored Cross-Site Scripting (XSS) vulnerability has been identified in the 'implement phase' of the API Publisher.
Published 2020-01-27 · Modified
4.8EPSS 0.008
CVE-2019-20438
An issue was discovered in WSO2 API Manager 2.6.0. A potential stored Cross-Site Scripting (XSS) vulnerability has been identified in the inline API documentation editor page of the API Publisher.
Published 2020-01-27 · Modified
4.8EPSS 0.008
CVE-2019-20443
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.
Published 2020-01-27 · Modified
4.8EPSS 0.008
CVE-2019-20440
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.
Published 2020-01-27 · Modified
4.8EPSS 0.008
CVE-2019-20442
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
Published 2020-01-27 · Modified
4.8EPSS 0.007
CVE-2019-15108
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
Published 2019-08-16 · Modified
4.8EPSS 0.006
CVE-2023-6911
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
Published 2023-12-18 · Modified
4.8EPSS 0.004
CVE-2025-4760
Authenticated Stored Cross-Site Scripting (XSS) in Multiple WSO2 Products via API Document Upload in Publisher
Published 2025-09-23 · Analyzed
4.8EPSS 0.002
CVE-2026-0637
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
4.4EPSS 0.002
CVE-2024-7097
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
Published 2025-05-30 · Analyzed
4.3EPSS 0.007
CVE-2024-6429
Content Spoofing in Multiple WSO2 Products via Error Message Injection
Published 2025-09-23 · Analyzed
4.3EPSS 0.002
CVE-2024-3511
Incorrect Authorization in Multiple WSO2 Products Allows Unauthorized Access to Registry Versioned Files
Published 2025-06-23 · Analyzed
4.3EPSS 0.002
CVE-2024-3509
Stored Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products via Rich Text Editor
Published 2025-06-02 · Analyzed
4.3EPSS 0.002
CVE-2019-6512
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.
Published 2019-05-14 · Modified
4.1EPSS 0.011
CVE-2025-13736
Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
Published 2026-08-06 · Analyzed
3.7EPSS 0.003
← Prev3 / 3