WSO2 LLC maintains a focused but strategically prominent portfolio of identity management, API gateway, and enterprise integration products that serve as critical infrastructure in authentication and access-control workflows across organizations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency to acquire public exploit code, reflecting the trust-boundary and data-handling demands of products positioned at organizational perimeters and identity layers. The exposure recurs across products such as API Manager, Identity Server, and Enterprise Integrator through weakness classes including cross-site scripting, XML external entity injection, authorization flaws, and server-side request forgery—attack patterns characteristic of web-facing middleware and authentication systems. Defenders should prioritize this vendor's security advisories given the sensitive data and authentication paths these products control, and inventory deployments across API gateways and identity services. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by WSO2 LLC over time
Of all the CVEs published by WSO2 LLC as a CNA, 97.0% affect products that WSO2 LLC develops as a vendor.
Of all the CVEs published that affect products developed by WSO2 LLC, 52.8% are self-published by WSO2 LLC as a CNA.
Signals from CVEs in this vendor scope (123 CVEs).
123 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29464CRITICAL Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers | Apr 18, 2022 | 9.8 | 98 | YES | YES |
CVE-2022-29548MEDIUM A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics | Apr 21, 2022 | 6.1 | 63 | NO | YES |
CVE-2022-39810MEDIUM An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatas | Sep 9, 2022 | 6.1 | 51 | NO | NO |
CVE-2020-24589CRITICAL The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. | Aug 21, 2020 | 9.1 | 50 | NO | YES |
CVE-2018-8716MEDIUM WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. | Apr 25, 2018 | 5.4 | 49 | NO | YES |
CVE-2020-17453MEDIUM WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. | Apr 5, 2021 | 6.1 | 44 | NO | YES |
CVE-2026-2053CRITICAL The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This om | Jun 26, 2026 | 10.0 | 42 | NO | NO |
CVE-2016-4311HIGH Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for | Feb 17, 2017 | 8.8 | 39 | NO | YES |
CVE-2016-4312HIGH XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to | Feb 17, 2017 | 7.5 | 37 | NO | YES |
CVE-2026-4249HIGH The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an u | Jul 6, 2026 | 8.6 | 36 | NO | NO |
Signals from CVEs in this vendor scope (123 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by WSO2 LLC.
Media articles that mention a CVE ID that affects a product developed by WSO2 LLC — matched by CVE ID, not by vendor name.