- EPSS 0.24%
- Veröffentlicht 06.08.2026 22:16:41
- Zuletzt bearbeitet 07.08.2026 18:17:06
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privilege...
CVE-2024-6541
- EPSS 0.26%
- Veröffentlicht 06.08.2026 22:16:40
- Zuletzt bearbeitet 07.08.2026 18:17:05
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should...
CVE-2025-13394
- EPSS 0.1%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 12.08.2026 19:53:27
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie a...
CVE-2024-6832
- EPSS 0.24%
- Veröffentlicht 06.08.2026 08:16:27
- Zuletzt bearbeitet 09.08.2026 14:14:01
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attemp...
CVE-2025-6670
- EPSS 0.23%
- Veröffentlicht 18.11.2025 11:28:37
- Zuletzt bearbeitet 08.12.2025 14:00:21
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the Same...
CVE-2025-10853
- EPSS 0.18%
- Veröffentlicht 05.11.2025 19:21:32
- Zuletzt bearbeitet 13.11.2025 15:31:45
A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the respons...
CVE-2025-11093
- EPSS 0.44%
- Veröffentlicht 05.11.2025 18:31:17
- Zuletzt bearbeitet 09.01.2026 02:33:37
An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integ...
CVE-2025-10907
- EPSS 0.56%
- Veröffentlicht 05.11.2025 18:15:33
- Zuletzt bearbeitet 04.12.2025 21:07:22
An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to...
CVE-2025-10713
- EPSS 0.42%
- Veröffentlicht 05.11.2025 17:18:24
- Zuletzt bearbeitet 04.12.2025 21:07:04
An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities. ...
CVE-2025-3125
- EPSS 0.86%
- Veröffentlicht 05.11.2025 14:49:44
- Zuletzt bearbeitet 04.12.2025 21:06:46
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-cont...