CVE-2025-13394
- EPSS 0.1%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 12.08.2026 19:53:27
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie a...
CVE-2024-8995
- EPSS 0.12%
- Veröffentlicht 06.08.2026 08:16:27
- Zuletzt bearbeitet 13.08.2026 13:18:42
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization...
CVE-2024-6832
- EPSS 0.24%
- Veröffentlicht 06.08.2026 08:16:27
- Zuletzt bearbeitet 09.08.2026 14:14:01
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attemp...
CVE-2024-10302
- EPSS 0.17%
- Veröffentlicht 06.08.2026 08:16:26
- Zuletzt bearbeitet 09.08.2026 14:25:39
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidate...
CVE-2026-2445
- EPSS 0.15%
- Veröffentlicht 20.07.2026 08:06:39
- Zuletzt bearbeitet 19.08.2026 19:29:34
The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacke...
CVE-2026-4249
- EPSS 0.34%
- Veröffentlicht 06.07.2026 10:16:56
- Zuletzt bearbeitet 09.07.2026 13:04:57
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can ...
CVE-2025-8591
- EPSS 0.16%
- Veröffentlicht 06.07.2026 10:16:53
- Zuletzt bearbeitet 09.07.2026 13:04:39
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. ...
CVE-2024-1248
- EPSS 0.18%
- Veröffentlicht 04.07.2026 20:38:49
- Zuletzt bearbeitet 09.07.2026 18:47:41
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning proc...
CVE-2025-13475
- EPSS 0.16%
- Veröffentlicht 04.07.2026 12:49:06
- Zuletzt bearbeitet 09.07.2026 17:55:35
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS appl...
- EPSS 0.24%
- Veröffentlicht 26.06.2026 07:26:15
- Zuletzt bearbeitet 27.06.2026 19:38:55
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to speci...