SecAlerts
w

wso2

Security Risk Profile

45
/100
medium

Security Risk Score

Comprehensive risk assessment based on 155 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 16, 2017 to present

155
Total CVEs
49
Critical+High
1
Exploited
20
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
20
Critical/High
Risk Level
45/100
medium
⚠️ 1 Active Exploits🆕 3Fresh (<7d)📈 5 in Last 30 Days

Severity Distribution

Critical
21
High
28
Medium
95
Low
5

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
11

Age Distribution

Common Weaknesses (CWE)

1
XSS
57
2
XEE
12
3
Input Validation
10
4
SSRF
8
5
Malicious File Upload
7

Most Affected Products

1. WSO2 API Manager467
2. WSO2 Identity Server346
3. WSO2 Identity Server as Key Manager115
4. WSO2 Enterprise Integrator55
5. WSO2 Api Control Plane44

Recent Vulnerabilities

See more →
CVE-2025-13166
CVSS 3.7low

Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery

Sep 15, 2026🔧 No Patch
CVE-2026-4103
CVSS 6.4medium

Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution

Sep 14, 2026🔧 No Patch
CVE-2026-3096
CVSS 4.7medium

Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft

Sep 10, 2026🔧 No Patch
CVE-2025-12737
CVSS 8.4high

Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution

Sep 3, 2026
CVE-2026-3416
CVSS 7.5high

Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads

Sep 3, 2026🔧 No Patch
CVE-2026-3418
CVSS 9.1critical

Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution

Aug 6, 2026🔧 No Patch
CVE-2026-3415
CVSS 8.7high

XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service

Aug 6, 2026🔧 No Patch
CVE-2025-14561
CVSS 9.0critical

Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations

Aug 6, 2026🔧 No Patch
CVE-2025-12317
CVSS 5.0medium

Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges

Aug 6, 2026🔧 No Patch
CVE-2025-6508
CVSS 4.3medium

User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information Exposure or Unintended Requests

Aug 6, 2026🔧 No Patch

Monitor wso2 in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.