Identity Server
Vendor:
First CVE: Feb 17, 2017 · Active for 9 years
70
Total CVEs
More Total CVEs than 98% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Identity Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2017
9 years ago
Most Recent CVE
Jul 6, 2026
20 days ago
CVE Severity & Scoring
Identity Server70 CVEs
64%
24%
10%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network63 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (10.0%)
Attack Complexity
Low66 (94.3%)
High4 (5.7%)
Unknown0 (0.0%)
User Interaction
None32 (45.7%)
Unknown0 (0.0%)
Required38 (54.3%)
Privileges Required
Low10 (14.3%)
High14 (20.0%)
None46 (65.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29464CRITICAL Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers | Apr 18, 2022 | 9.8 | 98 | YES | YES |
CVE-2022-29548MEDIUM A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics | Apr 21, 2022 | 6.1 | 63 | NO | YES |
CVE-2018-8716MEDIUM WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. | Apr 25, 2018 | 5.4 | 49 | NO | YES |
CVE-2020-17453MEDIUM WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. | Apr 5, 2021 | 6.1 | 44 | NO | YES |
CVE-2016-4311HIGH Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for | Feb 17, 2017 | 8.8 | 39 | NO | YES |
CVE-2016-4312HIGH XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to | Feb 17, 2017 | 7.5 | 37 | NO | YES |
CVE-2025-13475HIGH In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS | Jul 4, 2026 | 7.3 | 34 | NO | NO |
CVE-2025-10470HIGH The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. | May 11, 2026 | 8.6 | 34 | NO | NO |
CVE-2025-5605MEDIUM An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by | Oct 24, 2025 | 5.3 | 34 | NO | YES |
CVE-2025-10611CRITICAL Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be i | Oct 16, 2025 | 9.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (70 CVEs).
CISA KEV
1 CVE
1.4% of CVEs· 96th percentile
Metasploit
1 CVE
1.4% of CVEs· 96th percentile
Nuclei
7 CVEs
10.0% of CVEs· 97th percentile
ExploitDB
4 CVEs
5.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (70 CVEs).
Media Mentions
Signals from CVEs in this product scope (70 CVEs).
Top CNAs Publishing CVEs For Identity Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.2.0 | 2 | 9.3 | 0.2% | 0 | 0 |
| 7.1.0 | 10 | 7.3 | 0.4% | 0 | 2 |
| 7.0.0 | 23 | 6.3 | 0.4% | 0 | 3 |
| 6.1.0 | 24 | 6.4 | 0.4% | 0 | 3 |
| 6.0.0 | 24 | 6.4 | 0.4% | 0 | 3 |
| 5.9.0 | 11 | 7.1 | 4.5% | 0 | 2 |
| 5.8.0 | 16 | 6.8 | 0.9% | 0 | 1 |
| 5.7.0 | 18 | 6.5 | 3.1% | 0 | 2 |
| 5.6.0 | 10 | 7.0 | 4.5% | 0 | 2 |
| 5.5.0 | 12 | 7.1 | 3.9% | 0 | 2 |
| 5.4.1 | 8 | 6.8 | 0.4% | 0 | 1 |
| 5.4.0 | 8 | 6.8 | 0.4% | 0 | 1 |
| 5.3.0 | 8 | 7.1 | 0.9% | 0 | 2 |
| 5.2.0 | 6 | 6.3 | 0.4% | 0 | 1 |
| 5.11.0 | 29 | 6.5 | 1.9% | 0 | 4 |
| 5.10.0 | 29 | 6.4 | 1.9% | 0 | 4 |
| 5.1.0 | 2 | 8.2 | 4.7% | 0 | 2 |