VendorsWSO2identity_server_as_key_managerall versions
Vulnerabilities

WSO2 Identity Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
Published 2022-04-18 · Analyzed
10.0KEVEPSS 1.000
CVE-2025-10611
Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
Published 2025-10-16 · Analyzed
9.8EPSS 0.008
CVE-2024-6914
Incorrect Authorization in Multiple WSO2 Products via Account Recovery SOAP Admin Service Leading to Account Takeover
Published 2025-05-22 · Analyzed
9.8EPSS 0.007
CVE-2025-9312
Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products
Published 2025-11-18 · Analyzed
9.8EPSS 0.002
CVE-2025-9804
Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs
Published 2025-10-16 · Analyzed
9.6EPSS 0.006
CVE-2025-15039
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
9.4EPSS 0.004
CVE-2021-42646
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.
Published 2022-05-11 · Modified
9.1EPSS 0.037
CVE-2024-2374
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service
Published 2026-04-16 · Analyzed
9.1EPSS 0.004
CVE-2020-24703
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.
Published 2020-08-27 · Modified
8.8EPSS 0.011
CVE-2020-24705
An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an attacker-controlled server if the victim submits a crafted Try It request, aka Session Hijacking. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
Published 2020-08-27 · Modified
8.8EPSS 0.011
CVE-2025-6670
Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services
Published 2025-11-18 · Analyzed
8.8EPSS 0.002
CVE-2020-12719
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and earlier, and Identity Server Analytics 5.6.0 and earlier.
Published 2020-05-07 · Modified
8.7EPSS 0.010
CVE-2023-6837
Incorrect Authorization in Multiple WSO2 Products via Federated Authentication with JIT Provisioning Leading to User Impersonation
Published 2023-12-15 · Modified
8.5EPSS 0.005
CVE-2025-10907
Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Services Leading to Remote Code Execution
Published 2025-11-05 · Analyzed
8.4EPSS 0.006
CVE-2025-12737
Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution
Published 2026-09-03 · Analyzed
8.4EPSS 0.002
CVE-2023-6836
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
Published 2023-12-15 · Modified
7.5EPSS 0.005
CVE-2024-6832
Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks
Published 2026-08-06 · Analyzed
7.5EPSS 0.002
CVE-2025-3125
Authenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Leading to Remote Code Execution
Published 2025-11-05 · Analyzed
7.2EPSS 0.009
CVE-2025-1862
Authenticated Arbitrary File Upload in Multiple WSO2 Products via BPEL Uploader SOAP Service Leading to Remote Code Execution
Published 2025-09-26 · Analyzed
7.2EPSS 0.005
CVE-2025-0663
Potential cross-tenant account takeover vulnerability in Multiple WSO2 Products via Adaptive Authentication and Auto-Login
Published 2025-09-23 · Analyzed
6.8EPSS 0.002
CVE-2020-13883
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
Published 2020-06-06 · Modified
6.7EPSS 0.008
CVE-2024-7073
Unauthenticated Server-Side Request Forgery (SSRF) in Multiple WSO2 Products via SOAP Admin Services
Published 2025-06-02 · Analyzed
6.5EPSS 0.002
CVE-2022-29548
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.
Published 2022-04-21 · Modified
6.11 PoCEPSS 0.411
CVE-2020-17453
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Published 2021-04-05 · Modified
6.1EPSS 0.262
CVE-2020-14446
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
Published 2020-06-18 · Modified
6.1EPSS 0.008
CVE-2020-24706
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.
Published 2020-08-27 · Modified
6.1EPSS 0.008
CVE-2021-36760
In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. (recoverpassword.do also has an open redirect issue for a similar reason.)
Published 2021-12-07 · Modified
6.1EPSS 0.007
CVE-2020-24704
An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, API Manager Analytics 2.2.0, API Microgateway 2.2.0, Data Analytics Server 3.2.0, Enterprise Integrator through 6.6.0, IS as Key Manager 5.5.0, Identity Server 5.5.0 and 5.8.0, Identity Server Analytics 5.5.0, and IoT Server 3.3.0 and 3.3.1.
Published 2020-08-27 · Modified
6.1EPSS 0.007
CVE-2023-6838
Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.
Published 2023-12-15 · Modified
6.1EPSS 0.004
CVE-2025-8591
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
Published 2026-07-06 · Analyzed
6.1EPSS 0.003
CVE-2024-1440
Open Redirection in Multiple WSO2 Products via Multi-Option Authentication Endpoint
Published 2025-06-02 · Analyzed
6.1EPSS 0.002
CVE-2025-10853
Reflected Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products Due to Improper Output Encoding
Published 2025-11-05 · Analyzed
6.1EPSS 0.002
CVE-2025-5350
SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products
Published 2025-10-24 · Analyzed
5.9EPSS 0.006
CVE-2024-10302
Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure
Published 2026-08-06 · Undergoing Analysis
5.8EPSS 0.002
CVE-2018-20737
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
Published 2019-03-18 · Modified
5.4EPSS 0.010
CVE-2024-7096
Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw
Published 2025-05-30 · Modified
5.4EPSS 0.007
CVE-2020-14444
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy Administration user interface.
Published 2020-06-18 · Modified
5.4EPSS 0.007
CVE-2020-14445
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Basic Policy Editor user Interface.
Published 2020-06-18 · Modified
5.4EPSS 0.006
CVE-2025-13394
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
Published 2026-08-06 · Analyzed
5.4EPSS 0.001
CVE-2025-5605
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
Published 2025-10-24 · Analyzed
5.3EPSS 0.008
1 / 2Next →