WSO2 LLC

First CVE: Dec 15, 2023Active for: 3 years
67
CVEs Published
More CVEs Published than 64% of tracked CNAs
22.3
Avg CVEs / Year
More Avg CVEs / Year than 70% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by WSO2 LLC as a CNA, 97.0% affect products that WSO2 LLC develops as a vendor.

97.0%
Self-reported: 65Third-party: 2

Of all the CVEs published that affect products developed by WSO2 LLC, 52.8% are self-published by WSO2 LLC as a CNA.

52.8%
47.2%
Self-published: 65Published by other CNAs: 58

Trends Over Time

The number and severity of CVEs published by WSO2 LLC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2023
2 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

Top CVEs

All CVEs published by WSO2 LLC as a CNA, regardless of affected vendor or product.

67 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This om
Jun 26, 202610.042NONO
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an u
Jul 6, 20268.636NONO
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS
Jul 4, 20267.334NONO
The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth.
May 11, 20268.634NONO
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by
Oct 24, 20255.334NOYES
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registr
Oct 16, 20259.834NONO
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be i
Oct 16, 20259.834NONO
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended perm
May 11, 20268.832NONO
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to impro
Nov 18, 20259.832NONO
Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO
May 5, 20259.131NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA67 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network58 (86.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network9 (13.4%)
Attack Complexity
Low64 (95.5%)
High3 (4.5%)
Unknown0 (0.0%)
User Interaction
None43 (64.2%)
Unknown0 (0.0%)
Required24 (35.8%)
Privileges Required
Low9 (13.4%)
High15 (22.4%)
None43 (64.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (67 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.5% of CVEs· 92nd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by WSO2 LLC as a CNA.

Media Mentions

Media articles that mention a CVE ID published by WSO2 LLC as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs