CVEs (44)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wso2 2Identity Server Identity Server As Key ManagerJun 17, 2026 Jun 18, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy...Show more |
1Wso2 3Api Manager Api MicrogatewayIdentity Server As Key ManagerJun 17, 2026 Jun 6, 2020 N/A· v4 6.7 MEDIUM· v3 6.5 MEDIUM· v2 In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle. |
1Wso2 7Api Manager Api Manager AnalyticsApi Microgateway+4 moreJun 17, 2026 May 8, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as K...Show more |
1Wso2 3Api Manager Identity ServerIdentity Server As Key ManagerNov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product. |