CVE-2026-4249
- EPSS 0.34%
- Veröffentlicht 06.07.2026 10:16:56
- Zuletzt bearbeitet 09.07.2026 13:04:57
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can ...
CVE-2025-8591
- EPSS 0.16%
- Veröffentlicht 06.07.2026 10:16:53
- Zuletzt bearbeitet 06.10.2026 22:10:00
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. ...
CVE-2024-1248
- EPSS 0.18%
- Veröffentlicht 04.07.2026 20:38:49
- Zuletzt bearbeitet 09.07.2026 18:47:41
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning proc...
CVE-2025-13475
- EPSS 0.16%
- Veröffentlicht 04.07.2026 12:49:06
- Zuletzt bearbeitet 06.10.2026 22:10:00
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS appl...
- EPSS 0.24%
- Veröffentlicht 26.06.2026 07:26:15
- Zuletzt bearbeitet 27.06.2026 19:38:55
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to speci...
CVE-2025-8325
- EPSS 0.17%
- Veröffentlicht 11.05.2026 10:16:13
- Zuletzt bearbeitet 27.05.2026 19:41:03
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service A...
CVE-2025-8154
- EPSS 0.19%
- Veröffentlicht 11.05.2026 10:16:12
- Zuletzt bearbeitet 27.05.2026 19:42:10
In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious ac...
CVE-2024-8010
- EPSS 0.27%
- Veröffentlicht 16.04.2026 10:16:14
- Zuletzt bearbeitet 23.04.2026 15:35:27
The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vulnerability...
CVE-2025-6024
- EPSS 0.23%
- Veröffentlicht 16.04.2026 10:16:14
- Zuletzt bearbeitet 23.04.2026 15:35:04
The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the ...
CVE-2024-4867
- EPSS 0.2%
- Veröffentlicht 16.04.2026 10:16:13
- Zuletzt bearbeitet 23.04.2026 15:35:37
The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a ...