VendorsWSO2api_managerany version
Vulnerabilities

WSO2 API Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

39CVEs
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Published 2022-04-18 · Analyzed
10.0KEVEPSS 1.000
CVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Published 2026-08-06 · Analyzed
10.0KEVEPSS 0.006
CVE-2026-2053
Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
Published 2026-06-26 · Analyzed
10.0EPSS 0.004
CVE-2026-1728
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
Published 2026-08-06 · Analyzed
9.8EPSS 0.005
CVE-2025-15039
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
9.4EPSS 0.007
CVE-2020-24589
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Published 2020-08-21 · Modified
9.1EPSS 0.263
CVE-2025-2905
An XML External Entity (XXE) vulnerability in Multiple WSO2 Products
Published 2025-05-05 · Modified
9.1EPSS 0.013
CVE-2020-24590
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Published 2020-08-21 · Modified
9.1EPSS 0.013
CVE-2024-2374
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service
Published 2026-04-16 · Analyzed
9.1EPSS 0.004
CVE-2020-24705
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
Published 2020-08-27 · Modified
8.8EPSS 0.011
CVE-2025-8325
Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations
Published 2026-05-11 · Analyzed
8.8EPSS 0.002
CVE-2020-12719
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.
Published 2020-05-07 · Modified
8.7EPSS 0.010
CVE-2026-4249
Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
Published 2026-07-06 · Analyzed
8.6EPSS 0.006
CVE-2023-6837
Incorrect Authorization in Multiple WSO2 Products via Federated Authentication with JIT Provisioning Leading to User Impersonation
Published 2023-12-15 · Modified
8.5EPSS 0.005
CVE-2025-11093
Arbitrary Code Execution with higher privileged users in Multiple WSO2 Products via Script Mediator Engines (GraalJS and NashornJS)
Published 2025-11-05 · Analyzed
8.4EPSS 0.004
CVE-2025-12737
Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution
Published 2026-09-03 · Analyzed
8.4EPSS 0.002
CVE-2024-1524
A local user can be impersonated when using federated authentication with Silent JIT Provisioning.
Published 2026-02-24 · Analyzed
8.1EPSS 0.003
CVE-2023-6836
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
Published 2023-12-15 · Modified
7.5EPSS 0.005
CVE-2026-3416
Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads
Published 2026-09-03 · Analyzed
7.5EPSS 0.004
CVE-2024-8010
XML External Entity Injection via Publisher in WSO2 API Manager Allows Reading Arbitrary Files
Published 2026-04-16 · Analyzed
7.5EPSS 0.003
CVE-2025-8154
HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation
Published 2026-05-11 · Analyzed
7.5EPSS 0.002
CVE-2025-13475
Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure
Published 2026-07-04 · Analyzed
7.3EPSS 0.003
CVE-2020-13883
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
Published 2020-06-06 · Modified
6.7EPSS 0.008
CVE-2020-24591
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.
Published 2020-08-21 · Modified
6.5EPSS 0.010
CVE-2024-4598
Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediator
Published 2025-09-23 · Analyzed
6.5EPSS 0.003
CVE-2020-17453
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Published 2021-04-05 · Modified
6.1EPSS 0.262
CVE-2023-31664
A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter.
Published 2023-05-23 · Modified
6.1EPSS 0.012
CVE-2020-24706
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
Published 2020-08-27 · Modified
6.1EPSS 0.008
CVE-2020-17454
WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it is possible to inject an XSS payload into the owner POST parameter, which does not filter user inputs. By putting an XSS payload in place of a valid Owner Name, a modal box appears that writes an error message concatenated to the injected payload (without any form of data encoding). This can also be exploited via CSRF.
Published 2020-10-21 · Modified
6.1EPSS 0.008
CVE-2025-8591
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
Published 2026-07-06 · Analyzed
6.1EPSS 0.003
CVE-2026-2445
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification
Published 2026-07-20 · Analyzed
6.1EPSS 0.003
CVE-2024-10242
Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 API Manager Allows UI Modification and Redirection
Published 2026-04-16 · Analyzed
6.1EPSS 0.002
CVE-2024-4867
Cross-Site Scripting via Developer Portal in WSO2 API Manager Enables UI Modification and Information Retrieval
Published 2026-04-16 · Analyzed
5.4EPSS 0.002
CVE-2025-13394
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
Published 2026-08-06 · Analyzed
5.4EPSS 0.001
CVE-2024-1248
Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
Published 2026-07-04 · Analyzed
5.3EPSS 0.003
CVE-2024-8995
Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
Published 2026-08-06 · Analyzed
4.9EPSS 0.002
CVE-2019-15108
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
Published 2019-08-16 · Modified
4.8EPSS 0.006
CVE-2026-0637
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
4.4EPSS 0.002
CVE-2025-13736
Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
Published 2026-08-06 · Analyzed
3.7EPSS 0.003