wso2
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 144 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 16, 2017 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure
Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions
Improper Access Control via Secret Type Management API in WSO2 Identity Server
Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use]
Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
Monitor wso2 in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.