product of wso2
api control plane
Severity
Exploited
Being told
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| WSO2 Multiple Products Path Traversal Vulnerability CVE-2026-5430 | Severity critical Exploited yes |
| The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook… CVE-2026-3416 | Severity high |
| The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication… CVE-2025-15039 | Severity critical |
| The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF)… CVE-2025-13394 | Severity medium |
| An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal… CVE-2025-9804 | Severity medium |
| The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's… CVE-2025-8591 | Severity medium |