vendor

wso2

14 thingsrelated by NVD

Its products

identity server 12 api manager 8 api control plane 6 identity server as key manager 5 open banking am 5 open banking iam 5 traffic manager 5 universal gateway 5 enterprise integrator 2 open banking km 2 api manager analytics 1 data analytics server 1 enterprise mobility manager 1 enterprise service bus 1 identity server analytics 1

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

WSO2 Multiple Products Path Traversal Vulnerability
CVE-2026-5430
Severity critical Exploited yes
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook…
CVE-2026-3416
Severity high
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication…
CVE-2025-15039
Severity critical
The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic…
CVE-2025-14779
Severity low
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or…
CVE-2025-13909
Severity medium
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the…
CVE-2025-13736
Severity low
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants…
CVE-2025-13475
Severity high
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF)…
CVE-2025-13394
Severity medium
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This…
CVE-2025-12627
Severity low
Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce…
CVE-2025-12624
Severity medium
When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and…
CVE-2025-11850
Severity medium
The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper…
CVE-2025-10503
Severity medium
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal…
CVE-2025-9804
Severity medium
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's…
CVE-2025-8591
Severity medium