WSO2 Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for WSO2 products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

5

In CISA KEV

1

Beyond CISA KEV

4

Sensor Observed

0

Virtual Patch Available

0

WSO2 KEVs Added by Year

Loading...

5 WSO2 KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-5605

Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure

High Not in CISA 15 Feb 2026
CVE-2020-24589

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

High Not in CISA 25 Jun 2025
CVE-2024-7097

Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup

High Not in CISA 30 May 2025
CVE-2022-29464

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a...

Confirmed In CISA 25 Apr 2022
CVE-2020-17453

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

High Not in CISA 05 Apr 2021

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-290 — Authentication Bypass by Spoofing 1
  • CWE-611 — Improper Restriction of XML External Entity Reference 1
  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
  • CWE-863 — Incorrect Authorization 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology