product of wso2

api manager

8 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

WSO2 Multiple Products Path Traversal Vulnerability
CVE-2026-5430
Severity critical Exploited yes
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook…
CVE-2026-3416
Severity high
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication…
CVE-2025-15039
Severity critical
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the…
CVE-2025-13736
Severity low
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants…
CVE-2025-13475
Severity high
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF)…
CVE-2025-13394
Severity medium
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal…
CVE-2025-9804
Severity medium
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's…
CVE-2025-8591
Severity medium