CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wso2 6Api Control Plane Api ManagerEnterprise Integrator+3 moreJun 17, 2026 Nov 5, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute a...Show more |
An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contex...Show more |
1Wso2 7Api Manager Api Manager AnalyticsApi Microgateway+4 moreJun 17, 2026 Dec 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information. |
1Wso2 9Api Manager Api Manager AnalyticsApi Microgateway+6 moreJun 17, 2026 Apr 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgatew...Show more |
1Wso2 8Api Manager Api Manager AnalyticsApi Microgateway+5 moreJun 17, 2026 Apr 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. |