← Back

Api Manager

api_manager

Vendor: Wso2 • 93 CVEs

CVEs (93)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wso2
1Api Manager
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0. A reflected XSS attack could be performed in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful docName request...Show more
An issue was discovered in WSO2 API Manager 2.6.0. A reflected XSS attack could be performed in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful docName request parameter.Show less
1Wso2
1Api Manager
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Datasource creation page of the Management Console.
1Wso2
3Api Manager
Enterprise IntegratorIdentity Server
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType...Show more
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.Show less
1Wso2
3Api Manager
Enterprise IntegratorIdentity Server
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuth...Show more
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.Show less
1Wso2
1Api Manager
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0. A potential Stored Cross-Site Scripting (XSS) vulnerability has been identified in the 'implement phase' of the API Publisher.
1Wso2
1Api Manager
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.
1Wso2
1Api Manager
Jun 17, 2026
Aug 16, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
1Wso2
1Api Manager
Jun 17, 2026
May 21, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
1Wso2
1Api Manager
Jun 17, 2026
May 14, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.
1Wso2
1Api Manager
Jun 17, 2026
May 14, 2019
N/A· v4
4.1 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to...Show more
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.Show less
1Wso2
3Api Manager
Identity ServerIdentity Server As Key Manager
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
1Wso2
1Api Manager
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
1Wso2
17Api Manager
App ManagerApplication Server+14 more
May 13, 2026
Sep 21, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.