CVE-2025-8591Medium· 6.1▾ SunlitThe software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application.
By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
api_control_plane >= 4.5.0, < 4.5.0.44api_control_plane >= 4.6.0, < 4.6.0.8api_manager >= 3.1.0, < 3.1.0.355api_manager >= 3.2.0, < 3.2.0.459api_manager >= 3.2.1, < 3.2.1.78api_manager >= 4.0.0, < 4.0.0.380api_manager >= 4.1.0, < 4.1.0.243api_manager >= 4.2.0, < 4.2.0.183api_manager >= 4.3.0, < 4.3.0.94api_manager >= 4.4.0, < 4.4.0.58api_manager >= 4.5.0, < 4.5.0.43api_manager >= 4.6.0, < 4.6.0.7identity_server >= 5.10.0, < 5.10.0.384identity_server >= 6.0.0, < 6.0.0.255identity_server >= 7.0.0, < 7.0.0.131identity_server >= 7.1.0, < 7.1.0.51identity_server_as_key_manager >= 5.10.0, < 5.10.0.375open_banking_am >= 2.0.0, < 2.0.0.404open_banking_iam >= 2.0.0, < 2.0.0.424traffic_manager >= 4.5.0, < 4.5.0.42traffic_manager >= 4.6.0, < 4.6.0.7universal_gateway >= 4.5.0, < 4.5.0.42universal_gateway >= 4.6.0, < 4.6.0.7Upgrade past the affected range:
api_control_plane 4.6.0.8api_manager 4.6.0.7identity_server 7.1.0.51identity_server_as_key_manager 5.10.0.375open_banking_am 2.0.0.404open_banking_iam 2.0.0.424traffic_manager 4.6.0.7universal_gateway 4.6.0.7Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15039Critical· 9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured
CVE-2025-13394Medium· 5.4The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks
CVE-2025-9804Critical· 9.6An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs
CVE-2026-5430Critical· 10.0The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported
CVE-2026-3416Medium· 5.9The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation
CVE-2026-4103Medium· 6.4Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization