Enterprise Integrator

Vendor:

First CVE: Sep 21, 2017 · Active for 8 years

32
Total CVEs
More Total CVEs than 97% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
3.1%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Enterprise Integrator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2017
8 years ago
Most Recent CVE
Nov 18, 2025
252 days ago

CVE Severity & Scoring

Enterprise Integrator32 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (12.5%)
Attack Complexity
Low32 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (43.8%)
Unknown0 (0.0%)
Required18 (56.3%)
Privileges Required
Low3 (9.4%)
High13 (40.6%)
None16 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers
Apr 18, 20229.898YESYES
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics
Apr 21, 20226.163NOYES
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatas
Sep 9, 20226.151NONO
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
Apr 5, 20216.144NOYES
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by
Oct 24, 20255.334NOYES
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepte
Oct 24, 20254.829NOYES
An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applyi
Nov 5, 20259.128NONO
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Sep 21, 20174.828NOYES
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A
Oct 16, 20256.526NONO
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specif
Nov 18, 20258.825NONO

Exploit Exposure

Signals from CVEs in this product scope (32 CVEs).

CISA KEV
1 CVE
3.1% of CVEs· 98th percentile
Metasploit
1 CVE
3.1% of CVEs· 97th percentile
Nuclei
6 CVEs
18.8% of CVEs· 98th percentile
ExploitDB
1 CVE
3.1% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (32 CVEs).

Media Mentions

Signals from CVEs in this product scope (32 CVEs).

Top CNAs Publishing CVEs For Enterprise Integrator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.6.0156.13.1%03
6.5.065.47.3%01
6.4.055.819.9%01
6.3.055.98.6%01
6.2.055.98.6%01
6.1.135.11.5%01
6.1.025.30.3%00
6.0.015.70.2%00