api_control_plane vulnerabilities
CVEs whose affected-version data names the api_control_plane package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2025-5802Medium· 5.3The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence
The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error messag…
CVE-2026-4103Medium· 6.4Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization
Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affec…
CVE-2026-3096Medium· 4.7The product's web portals allow external links to be opened in a new browser tab
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navig…
CVE-2026-3416Medium· 5.9The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a s…
CVE-2025-12737High· 8.4The administrative operations within the Carbon Console do not adequately validate specific user-supplied input
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Succe…
CVE-2024-6832Medium· 5.9The account locking mechanism fails to trigger when secondary user stores are inaccessible
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repe…
CVE-2024-10302Medium· 4.0The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowi…