CVE-2024-10302
- EPSS 0.17%
- Veröffentlicht 06.08.2026 08:16:26
- Zuletzt bearbeitet 09.08.2026 14:25:39
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidate...
CVE-2026-2445
- EPSS 0.15%
- Veröffentlicht 20.07.2026 08:06:39
- Zuletzt bearbeitet 19.08.2026 19:29:34
The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacke...
CVE-2026-4249
- EPSS 0.34%
- Veröffentlicht 06.07.2026 10:16:56
- Zuletzt bearbeitet 09.07.2026 13:04:57
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can ...
CVE-2025-8591
- EPSS 0.16%
- Veröffentlicht 06.07.2026 10:16:53
- Zuletzt bearbeitet 09.07.2026 13:04:39
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. ...
CVE-2025-8325
- EPSS 0.17%
- Veröffentlicht 11.05.2026 10:16:13
- Zuletzt bearbeitet 27.05.2026 19:41:03
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service A...
CVE-2025-8154
- EPSS 0.19%
- Veröffentlicht 11.05.2026 10:16:12
- Zuletzt bearbeitet 27.05.2026 19:42:10
In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious ac...
CVE-2025-13590
- EPSS 0.68%
- Veröffentlicht 19.02.2026 10:05:06
- Zuletzt bearbeitet 20.02.2026 21:19:23
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malic...
CVE-2025-9312
- EPSS 0.24%
- Veröffentlicht 18.11.2025 12:05:22
- Zuletzt bearbeitet 08.12.2025 14:01:26
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain d...
CVE-2025-6670
- EPSS 0.23%
- Veröffentlicht 18.11.2025 11:28:37
- Zuletzt bearbeitet 08.12.2025 14:00:21
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the Same...
CVE-2025-10853
- EPSS 0.18%
- Veröffentlicht 05.11.2025 19:21:32
- Zuletzt bearbeitet 13.11.2025 15:31:45
A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the respons...