Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

WSO2 LLC

First CVE: Feb 17, 2017Active for: 9 yearsTotal CVEs: 123
53.0
VTI Score
TOP TARGET

WSO2 LLC maintains a focused but strategically prominent portfolio of identity management, API gateway, and enterprise integration products that serve as critical infrastructure in authentication and access-control workflows across organizations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency to acquire public exploit code, reflecting the trust-boundary and data-handling demands of products positioned at organizational perimeters and identity layers. The exposure recurs across products such as API Manager, Identity Server, and Enterprise Integrator through weakness classes including cross-site scripting, XML external entity injection, authorization flaws, and server-side request forgery—attack patterns characteristic of web-facing middleware and authentication systems. Defenders should prioritize this vendor's security advisories given the sensitive data and authentication paths these products control, and inventory deployments across API gateways and identity services. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
123
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.8%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by WSO2 LLC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2017
9 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

Self-Reporting Analysis

Of all the CVEs published by WSO2 LLC as a CNA, 97.0% affect products that WSO2 LLC develops as a vendor.

97.0%
Self-reported: 65 (97.0%)
Third-party: 2 (3.0%)

Of all the CVEs published that affect products developed by WSO2 LLC, 52.8% are self-published by WSO2 LLC as a CNA.

52.8%
47.2%
Self-published: 65 (52.8%)
Other CNAs: 58 (47.2%)

Products(35 total)

Top CVEs

Signals from CVEs in this vendor scope (123 CVEs).

123 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-29464CRITICAL
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers
Apr 18, 20229.898YESYES
CVE-2022-29548MEDIUM
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics
Apr 21, 20226.163NOYES
CVE-2022-39810MEDIUM
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatas
Sep 9, 20226.151NONO
CVE-2020-24589CRITICAL
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Aug 21, 20209.150NOYES
CVE-2018-8716MEDIUM
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
Apr 25, 20185.449NOYES
CVE-2020-17453MEDIUM
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Apr 5, 20216.144NOYES
CVE-2026-2053CRITICAL
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This om
Jun 26, 202610.042NONO
CVE-2016-4311HIGH
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for
Feb 17, 20178.839NOYES
CVE-2016-4312HIGH
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to
Feb 17, 20177.537NOYES
CVE-2026-4249HIGH
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an u
Jul 6, 20268.636NONO
View all 123 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products123 CVEs
68%
20%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network115 (93.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network8 (6.5%)
Attack Complexity
Low119 (96.7%)
High4 (3.3%)
Unknown0 (0.0%)
User Interaction
None57 (46.3%)
Unknown0 (0.0%)
Required66 (53.7%)
Privileges Required
Low18 (14.6%)
High31 (25.2%)
None74 (60.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (123 CVEs).

CISA KEV
1 CVE
0.8% of CVEs· 99th percentile
Metasploit
1 CVE
0.8% of CVEs· 97th percentile
Nuclei
8 CVEs
6.5% of CVEs· 96th percentile
ExploitDB
7 CVEs
5.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by WSO2 LLC.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by WSO2 LLC — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For WSO2 LLC's Products

View all 5 CNAs →

Top CWEs