WSO2 Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for WSO2 products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
5
In CISA KEV
1
Beyond CISA KEV
4
Sensor Observed
0
Virtual Patch Available
0
WSO2 KEVs Added by Year
5 WSO2 KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-5605
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure |
WSO2 Identity Server, WSO2 Enterprise Integrator, WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Manager, WSO2 API Control Plane, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, org.wso2.carbon:org.wso2.carbon.ui | High | Not in CISA | 15 Feb 2026 |
|
CVE-2020-24589
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. |
API Manager | High | Not in CISA | 25 Jun 2025 |
|
CVE-2024-7097
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup |
WSO2 Open Banking AM, WSO2 Open Banking KM, WSO2 Identity Server as Key Manager, WSO2 API Manager, WSO2 Identity Server, WSO2 Open Banking IAM, WSO2 Enterprise Mobility Manager | High | Not in CISA | 30 May 2025 |
|
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a... |
WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server Analytics, WSO2 Enterprise Integrator, WSO2 Open Banking AM, WSO2 Open Banking KM | Confirmed | In CISA | 25 Apr 2022 |
|
CVE-2020-17453
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. |
WSO2 Management Console | High | Not in CISA | 05 Apr 2021 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-290 — Authentication Bypass by Spoofing 1
- CWE-611 — Improper Restriction of XML External Entity Reference 1
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
- CWE-863 — Incorrect Authorization 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology