Enterprise Integrator
Vendor:
First CVE: Sep 21, 2017 · Active for 8 years
32
Total CVEs
More Total CVEs than 97% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
3.1%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Enterprise Integrator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2017
8 years ago
Most Recent CVE
Nov 18, 2025
252 days ago
CVE Severity & Scoring
Enterprise Integrator32 CVEs
66%
28%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (12.5%)
Attack Complexity
Low32 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (43.8%)
Unknown0 (0.0%)
Required18 (56.3%)
Privileges Required
Low3 (9.4%)
High13 (40.6%)
None16 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29464CRITICAL Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers | Apr 18, 2022 | 9.8 | 98 | YES | YES |
CVE-2022-29548MEDIUM A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics | Apr 21, 2022 | 6.1 | 63 | NO | YES |
CVE-2022-39810MEDIUM An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatas | Sep 9, 2022 | 6.1 | 51 | NO | NO |
CVE-2020-17453MEDIUM WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. | Apr 5, 2021 | 6.1 | 44 | NO | YES |
CVE-2025-5605MEDIUM An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by | Oct 24, 2025 | 5.3 | 34 | NO | YES |
CVE-2025-5350MEDIUM SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepte | Oct 24, 2025 | 4.8 | 29 | NO | YES |
CVE-2025-10713CRITICAL An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applyi | Nov 5, 2025 | 9.1 | 28 | NO | NO |
CVE-2017-14651MEDIUM WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. | Sep 21, 2017 | 4.8 | 28 | NO | YES |
CVE-2025-9804MEDIUM An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A | Oct 16, 2025 | 6.5 | 26 | NO | NO |
CVE-2025-6670HIGH A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specif | Nov 18, 2025 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (32 CVEs).
CISA KEV
1 CVE
3.1% of CVEs· 98th percentile
Metasploit
1 CVE
3.1% of CVEs· 97th percentile
Nuclei
6 CVEs
18.8% of CVEs· 98th percentile
ExploitDB
1 CVE
3.1% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (32 CVEs).
Media Mentions
Signals from CVEs in this product scope (32 CVEs).
Top CNAs Publishing CVEs For Enterprise Integrator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.6.0 | 15 | 6.1 | 3.1% | 0 | 3 |
| 6.5.0 | 6 | 5.4 | 7.3% | 0 | 1 |
| 6.4.0 | 5 | 5.8 | 19.9% | 0 | 1 |
| 6.3.0 | 5 | 5.9 | 8.6% | 0 | 1 |
| 6.2.0 | 5 | 5.9 | 8.6% | 0 | 1 |
| 6.1.1 | 3 | 5.1 | 1.5% | 0 | 1 |
| 6.1.0 | 2 | 5.3 | 0.3% | 0 | 0 |
| 6.0.0 | 1 | 5.7 | 0.2% | 0 | 0 |