SecAlerts
wso2 logo

wso2

Security Risk Profile

45
/100
medium

Security Risk Score

Comprehensive risk assessment based on 144 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 16, 2017 to present

144
Total CVEs
43
Critical+High
1
Exploited
14
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
14
Critical/High
Risk Level
45/100
medium
⚠️ 1 Active Exploits🆕 12Fresh (<7d)📈 13 in Last 30 Days

Severity Distribution

Critical
19
High
24
Medium
91
Low
4

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
11

Age Distribution

Common Weaknesses (CWE)

1
XSS
55
2
XEE
12
3
Input Validation
8
4
SSRF
8
5
CSRF
6

Most Affected Products

1. WSO2 API Manager373
2. WSO2 Identity Server286
3. WSO2 Identity Server as Key Manager105
4. WSO2 Enterprise Integrator54
5. WSO2 Open Banking AM31

Recent Vulnerabilities

See more →
CVE-2026-5430
CVSS 10.0critical

Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover

8/6/2026🔧 No Patch
CVE-2026-1728
CVSS 9.8critical

Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover

8/6/2026🔧 No Patch
CVE-2025-15039
CVSS 9.4critical

Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products

8/6/2026🔧 No Patch
CVE-2026-0637
CVSS 4.4medium

Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products

8/6/2026🔧 No Patch
CVE-2025-13394
CVSS 5.4medium

Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions

8/6/2026🔧 No Patch
CVE-2025-13909
CVSS 4.3medium

Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure

8/6/2026🔧 No Patch
CVE-2025-12627
CVSS 2.4low

Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions

8/6/2026🔧 No Patch
CVE-2025-14779
CVSS 3.8low

Improper Access Control via Secret Type Management API in WSO2 Identity Server

8/6/2026🔧 No Patch
CVE-2025-11850
CVSS 4.3medium

Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use]

8/6/2026🔧 No Patch
CVE-2025-13736
CVSS 3.7low

Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery

8/6/2026🔧 No Patch

Monitor wso2 in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.