VendorsWSO2identity_serverany version
Vulnerabilities

WSO2 Identity Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

31CVEs
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Published 2022-04-18 · Analyzed
10.0KEVEPSS 1.000
CVE-2025-15039
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
9.4EPSS 0.007
CVE-2024-2374
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service
Published 2026-04-16 · Analyzed
9.1EPSS 0.004
CVE-2020-24705
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
Published 2020-08-27 · Modified
8.8EPSS 0.011
CVE-2020-12719
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.
Published 2020-05-07 · Modified
8.7EPSS 0.010
CVE-2025-10470
Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability
Published 2026-05-11 · Analyzed
8.6EPSS 0.003
CVE-2023-6837
Incorrect Authorization in Multiple WSO2 Products via Federated Authentication with JIT Provisioning Leading to User Impersonation
Published 2023-12-15 · Modified
8.5EPSS 0.005
CVE-2025-12737
Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution
Published 2026-09-03 · Analyzed
8.4EPSS 0.002
CVE-2024-1524
A local user can be impersonated when using federated authentication with Silent JIT Provisioning.
Published 2026-02-24 · Analyzed
8.1EPSS 0.003
CVE-2025-13475
Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure
Published 2026-07-04 · Analyzed
7.3EPSS 0.003
CVE-2025-10908
Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized Access
Published 2026-05-11 · Analyzed
7.3EPSS 0.002
CVE-2025-9973
Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover
Published 2026-05-11 · Analyzed
7.2EPSS 0.004
CVE-2020-17453
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Published 2021-04-05 · Modified
6.1EPSS 0.262
CVE-2020-14446
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
Published 2020-06-18 · Modified
6.1EPSS 0.008
CVE-2020-24706
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
Published 2020-08-27 · Modified
6.1EPSS 0.008
CVE-2025-8591
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
Published 2026-07-06 · Analyzed
6.1EPSS 0.003
CVE-2026-2445
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification
Published 2026-07-20 · Analyzed
6.1EPSS 0.003
CVE-2025-10503
Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 Identity Server
Published 2026-04-29 · Analyzed
6.1EPSS 0.002
CVE-2018-8716
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
Published 2018-04-25 · Modified
5.41 PoCEPSS 0.387
CVE-2020-14444
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy Administration user interface.
Published 2020-06-18 · Modified
5.4EPSS 0.007
CVE-2020-14445
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Basic Policy Editor user Interface.
Published 2020-06-18 · Modified
5.4EPSS 0.006
CVE-2025-13394
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
Published 2026-08-06 · Analyzed
5.4EPSS 0.001
CVE-2024-1248
Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
Published 2026-07-04 · Analyzed
5.3EPSS 0.003
CVE-2024-0391
Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery
Published 2026-05-11 · Analyzed
5.3EPSS 0.002
CVE-2024-8995
Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
Published 2026-08-06 · Analyzed
4.9EPSS 0.002
CVE-2026-0637
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
4.4EPSS 0.002
CVE-2025-13909
Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure
Published 2026-08-06 · Analyzed
4.3EPSS 0.003
CVE-2025-11850
Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use]
Published 2026-08-06 · Analyzed
4.3EPSS 0.003
CVE-2025-14779
Improper Access Control via Secret Type Management API in WSO2 Identity Server
Published 2026-08-06 · Analyzed
3.8EPSS 0.003
CVE-2025-13736
Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
Published 2026-08-06 · Analyzed
3.7EPSS 0.003
CVE-2025-12627
Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions
Published 2026-08-06 · Analyzed
2.4EPSS 0.002