VulnSea

wso2 has 10 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 5.9 (medium). None have a confirmed exploitation report. Most affected products: api_control_plane (4), WSO2 API Control Plane (2), WSO2 API Manager (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
Last 90 days
9 prev 0

Products

  • api_control_plane 4
  • WSO2 API Control Plane 2
  • WSO2 API Manager 1
  • WSO2 Identity Server 1
  • WSO2 Integrator: MI for Visual Studio Code 1
  • identity_server 1
10
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

wso2 vulnerabilities

CVEs affecting wso2, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-19515High· 7.0
1w ago

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary op…

TwilightWSO2 · WSO2 Integrator: MI for Visual Studio CodeEPSS 0.14%via NVD
CVE-2025-5802Medium· 5.3
1w ago

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error messag…

SunlitWSO2 · WSO2 API ManagerEPSS 0.25%via NVD
CVE-2025-13166Low· 3.7
1w ago

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …

SunlitWSO2 · WSO2 Identity ServerEPSS 0.22%via NVD
CVE-2026-4103Medium· 6.4
1w ago

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affec…

SunlitWSO2 · WSO2 API Control PlaneEPSS 0.18%via NVD
CVE-2026-3096Medium· 4.7
1w ago

The product's web portals allow external links to be opened in a new browser tab

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navig…

SunlitWSO2 · WSO2 API Control PlaneEPSS 0.21%via NVD
CVE-2026-3416Medium· 5.9
2w ago

The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation

The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a s…

Sunlitwso2 · api_control_planeEPSS 0.26%via NVD
CVE-2025-12737High· 8.4
2w ago

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Succe…

Twilightwso2 · api_control_planeEPSS 0.22%via NVD
CVE-2024-6832Medium· 5.9
1mo ago

The account locking mechanism fails to trigger when secondary user stores are inaccessible

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repe…

Sunlitwso2 · api_control_planeEPSS 0.24%via NVD
CVE-2024-10302Medium· 4.0
1mo ago

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowi…

Sunlitwso2 · api_control_planeEPSS 0.17%via NVD
CVE-2025-12107High· 8.4
7mo ago

The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input

The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary …

Twilightwso2 · identity_serverEPSS 0.65%via NVD
wso2 vulnerabilities (CVEs) · VulnSea