Open Banking Am
Vendor:
First CVE: Apr 18, 2022 · Active for 4 years
19
Total CVEs
More Total CVEs than 95% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
5.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Open Banking Am over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2022
4 years ago
Most Recent CVE
Jul 6, 2026
21 days ago
CVE Severity & Scoring
Open Banking Am19 CVEs
53%
16%
32%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (78.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (21.1%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (73.7%)
Unknown0 (0.0%)
Required5 (26.3%)
Privileges Required
Low1 (5.3%)
High3 (15.8%)
None15 (78.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29464CRITICAL Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers | Apr 18, 2022 | 9.8 | 98 | YES | YES |
CVE-2025-5605MEDIUM An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by | Oct 24, 2025 | 5.3 | 34 | NO | YES |
CVE-2025-10611CRITICAL Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be i | Oct 16, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9312CRITICAL A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to impro | Nov 18, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-5350MEDIUM SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepte | Oct 24, 2025 | 4.8 | 29 | NO | YES |
CVE-2024-6914CRITICAL An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exp | May 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-8591MEDIUM The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to | Jul 6, 2026 | 6.1 | 28 | NO | NO |
CVE-2024-1248MEDIUM The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user | Jul 4, 2026 | 5.3 | 28 | NO | NO |
CVE-2025-10713CRITICAL An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applyi | Nov 5, 2025 | 9.1 | 28 | NO | NO |
CVE-2024-2374CRITICAL The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malici | Apr 16, 2026 | 9.1 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
1 CVE
5.3% of CVEs· 98th percentile
Metasploit
1 CVE
5.3% of CVEs· 97th percentile
Nuclei
4 CVEs
21.1% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Open Banking Am
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.0 | 15 | 6.9 | 0.5% | 0 | 3 |
| 1.5.0 | 5 | 8.3 | 0.5% | 0 | 0 |
| 1.4.0 | 5 | 8.3 | 0.5% | 0 | 0 |
| 1.3.0 | 2 | 7.6 | 0.6% | 0 | 0 |