WSO2 LLC
First CVE: Dec 15, 2023Active for: 3 years
67
CVEs Published
More CVEs Published than 64% of tracked CNAs
22.3
Avg CVEs / Year
More Avg CVEs / Year than 70% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by WSO2 LLC as a CNA, 97.0% affect products that WSO2 LLC develops as a vendor.
97.0%
Self-reported: 65Third-party: 2
Of all the CVEs published that affect products developed by WSO2 LLC, 52.8% are self-published by WSO2 LLC as a CNA.
52.8%
47.2%
Self-published: 65Published by other CNAs: 58
Trends Over Time
The number and severity of CVEs published by WSO2 LLC over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2023
2 years ago
Most Recent CVE
Jul 20, 2026
4 days ago
Top CVEs
All CVEs published by WSO2 LLC as a CNA, regardless of affected vendor or product.
67 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2053CRITICAL The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This om | Jun 26, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-4249HIGH The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an u | Jul 6, 2026 | 8.6 | 36 | NO | NO |
CVE-2025-13475HIGH In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS | Jul 4, 2026 | 7.3 | 34 | NO | NO |
CVE-2025-10470HIGH The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. | May 11, 2026 | 8.6 | 34 | NO | NO |
CVE-2025-5605MEDIUM An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by | Oct 24, 2025 | 5.3 | 34 | NO | YES |
CVE-2025-9152CRITICAL An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registr | Oct 16, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10611CRITICAL Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be i | Oct 16, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-8325HIGH The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended perm | May 11, 2026 | 8.8 | 32 | NO | NO |
CVE-2025-9312CRITICAL A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to impro | Nov 18, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-2905CRITICAL Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO | May 5, 2025 | 9.1 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA67 CVEs
58%
28%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network58 (86.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network9 (13.4%)
Attack Complexity
Low64 (95.5%)
High3 (4.5%)
Unknown0 (0.0%)
User Interaction
None43 (64.2%)
Unknown0 (0.0%)
Required24 (35.8%)
Privileges Required
Low9 (13.4%)
High15 (22.4%)
None43 (64.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (67 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.5% of CVEs· 92nd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by WSO2 LLC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by WSO2 LLC as a CNA — matched by CVE ID, not by organization name.