VendorsWSO2identity_server_as_key_managerall versions
Vulnerabilities

WSO2 Identity Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2024-1248
Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
Published 2026-07-04 · Analyzed
5.3EPSS 0.003
CVE-2025-1396
Username Enumeration in Multiple WSO2 Products with Multi-Attribute Login Enabled
Published 2025-09-26 · Analyzed
5.3EPSS 0.003
CVE-2024-0391
Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery
Published 2026-05-11 · Analyzed
5.3EPSS 0.002
CVE-2024-8008
Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection Validation
Published 2025-06-02 · Analyzed
5.2EPSS 0.005
CVE-2024-8995
Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
Published 2026-08-06 · Analyzed
4.9EPSS 0.002
CVE-2023-6911
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
Published 2023-12-18 · Modified
4.8EPSS 0.004
CVE-2026-0637
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
4.4EPSS 0.002
CVE-2024-7097
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
Published 2025-05-30 · Analyzed
4.3EPSS 0.007
CVE-2024-3511
Incorrect Authorization in Multiple WSO2 Products Allows Unauthorized Access to Registry Versioned Files
Published 2025-06-23 · Analyzed
4.3EPSS 0.002
CVE-2024-3509
Stored Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products via Rich Text Editor
Published 2025-06-02 · Analyzed
4.3EPSS 0.002
CVE-2025-0672
Authentication Bypass in Multiple WSO2 Products via Stale FIDO Credential Association
Published 2025-09-23 · Analyzed
3.8EPSS 0.002
CVE-2025-13736
Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
Published 2026-08-06 · Analyzed
3.7EPSS 0.003
← Prev2 / 2