Api Manager
Vendor:
First CVE: Sep 21, 2017 · Active for 8 years
83
Total CVEs
More Total CVEs than 99% of tracked products
10.4
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
1.2%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Api Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2017
8 years ago
Most Recent CVE
Jul 6, 2026
18 days ago
CVE Severity & Scoring
Api Manager83 CVEs
64%
20%
16%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network78 (94.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (6.0%)
Attack Complexity
Low80 (96.4%)
High3 (3.6%)
Unknown0 (0.0%)
User Interaction
None41 (49.4%)
Unknown0 (0.0%)
Required42 (50.6%)
Privileges Required
Low9 (10.8%)
High23 (27.7%)
None51 (61.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (83 CVEs).
83 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29464CRITICAL Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers | Apr 18, 2022 | 9.8 | 98 | YES | YES |
CVE-2022-29548MEDIUM A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics | Apr 21, 2022 | 6.1 | 63 | NO | YES |
CVE-2020-24589CRITICAL The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. | Aug 21, 2020 | 9.1 | 50 | NO | YES |
CVE-2020-17453MEDIUM WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. | Apr 5, 2021 | 6.1 | 44 | NO | YES |
CVE-2026-2053CRITICAL The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This om | Jun 26, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-4249HIGH The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an u | Jul 6, 2026 | 8.6 | 36 | NO | NO |
CVE-2025-13475HIGH In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS | Jul 4, 2026 | 7.3 | 34 | NO | NO |
CVE-2025-5605MEDIUM An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by | Oct 24, 2025 | 5.3 | 34 | NO | YES |
CVE-2025-9152CRITICAL An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registr | Oct 16, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10611CRITICAL Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be i | Oct 16, 2025 | 9.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (83 CVEs).
CISA KEV
1 CVE
1.2% of CVEs· 96th percentile
Metasploit
1 CVE
1.2% of CVEs· 96th percentile
Nuclei
8 CVEs
9.6% of CVEs· 97th percentile
ExploitDB
1 CVE
1.2% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (83 CVEs).
Media Mentions
Signals from CVEs in this product scope (83 CVEs).
Top CNAs Publishing CVEs For Api Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.6.0 | 2 | 8.0 | 0.4% | 0 | 0 |
| 4.5.0 | 15 | 7.3 | 0.5% | 0 | 2 |
| 4.4.0 | 16 | 7.1 | 0.5% | 0 | 2 |
| 4.3.0 | 24 | 6.7 | 0.4% | 0 | 3 |
| 4.2.0 | 25 | 6.6 | 0.4% | 0 | 3 |
| 4.1.0 | 23 | 6.6 | 0.4% | 0 | 3 |
| 4.0.0 | 27 | 6.7 | 2.1% | 0 | 4 |
| 3.2.1 | 22 | 6.7 | 0.4% | 0 | 3 |
| 3.2.0 | 29 | 6.5 | 2.0% | 0 | 4 |
| 3.1.0 | 24 | 6.7 | 2.3% | 0 | 4 |
| 3.0.0 | 13 | 7.2 | 4.0% | 0 | 2 |
| 2.6.0 | 25 | 5.9 | 2.6% | 0 | 2 |
| 2.5.0 | 9 | 6.9 | 5.0% | 0 | 2 |
| 2.2.0 | 11 | 7.0 | 4.3% | 0 | 2 |
| 2.1.0 | 5 | 6.2 | 1.3% | 0 | 2 |
| 2.0.0 | 2 | 6.0 | 0.6% | 0 | 0 |