← Back

Wso2

wso2

123 CVEs • 35 products

Products (35)

Click to collapse
Toggle
Api Manager
api_manager
Iot Server
iot_server
Carbon
carbon
App Manager
app_manager
Storage Server
storage_server
Transport Http
transport-http

CVEs (123)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wso2
3Api Manager
Enterprise IntegratorIdentity Server
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuth...Show more
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.Show less
1Wso2
1Api Manager
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0. A potential Stored Cross-Site Scripting (XSS) vulnerability has been identified in the 'implement phase' of the API Publisher.
1Wso2
1Api Manager
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.
1Wso2
1Enterprise Integrator
Jun 17, 2026
Dec 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the source view in the Management Console.
1Wso2
1Identity Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
1Wso2
1Identity Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
1Wso2
1Api Manager
Jun 17, 2026
Aug 16, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
1Wso2
1Api Manager
Jun 17, 2026
May 21, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
1Wso2
1Dashboard Server
Jun 17, 2026
May 14, 2019
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-sc...Show more
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF.Show less
1Wso2
1Api Manager
Jun 17, 2026
May 14, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.
1Wso2
1Dashboard Server
Jun 17, 2026
May 14, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.
1Wso2
1Api Manager
Jun 17, 2026
May 14, 2019
N/A· v4
4.1 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to...Show more
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF network scanning), or to enumerate files because of the existence of the file:// wrapper.Show less
1Wso2
3Api Manager
Identity ServerIdentity Server As Key Manager
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
1Wso2
1Api Manager
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
1Wso2
1Identity Server
Jun 17, 2026
Apr 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
1Wso2
8Application Server
Business Process ServerBusiness Rules Server+5 more
May 13, 2026
Oct 4, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3...Show more
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.Show less
1Wso2
17Api Manager
App ManagerApplication Server+14 more
May 13, 2026
Sep 21, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
1Wso2
1Enablement Server For Java
May 13, 2026
Feb 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
1Wso2
1Carbon
May 13, 2026
Feb 17, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType...Show more
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp.Show less
1Wso2
1Carbon
May 13, 2026
Feb 17, 2017
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/prox...Show more
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.Show less