Api Control Plane

Vendor:

First CVE: Sep 23, 2025 · Active for under a year

20
Total CVEs
More Total CVEs than 94% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Api Control Plane over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2025
9 months ago
Most Recent CVE
Jul 6, 2026
18 days ago

CVE Severity & Scoring

Api Control Plane20 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (70.0%)
Unknown0 (0.0%)
Required6 (30.0%)
Privileges Required
Low2 (10.0%)
High7 (35.0%)
None11 (55.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an u
Jul 6, 20268.636NONO
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by
Oct 24, 20255.334NOYES
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registr
Oct 16, 20259.834NONO
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be i
Oct 16, 20259.834NONO
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended perm
May 11, 20268.832NONO
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to impro
Nov 18, 20259.832NONO
In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected
May 11, 20267.529NONO
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead
Feb 19, 20267.229NONO
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepte
Oct 24, 20254.829NOYES
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to
Jul 6, 20266.128NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Api Control Plane

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.6.028.00.4%00
4.5.0157.30.5%02