Open Banking Iam

Vendor:

First CVE: Apr 18, 2022 · Active for 4 years

25
Total CVEs
More Total CVEs than 96% of tracked products
8.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 39% of tracked products
4.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Open Banking Iam over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2022
4 years ago
Most Recent CVE
Jul 6, 2026
22 days ago

CVE Severity & Scoring

Open Banking Iam25 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (76.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network6 (24.0%)
Attack Complexity
Low25 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (76.0%)
Unknown0 (0.0%)
Required6 (24.0%)
Privileges Required
Low1 (4.0%)
High6 (24.0%)
None18 (72.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers
Apr 18, 20229.898YESYES
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by
Oct 24, 20255.334NOYES
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be i
Oct 16, 20259.834NONO
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to impro
Nov 18, 20259.832NONO
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepte
Oct 24, 20254.829NOYES
An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exp
May 22, 20259.829NONO
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to
Jul 6, 20266.128NONO
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user
Jul 4, 20265.328NONO
An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applyi
Nov 5, 20259.128NONO
The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malici
Apr 16, 20269.127NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
1 CVE
4.0% of CVEs· 98th percentile
Metasploit
1 CVE
4.0% of CVEs· 97th percentile
Nuclei
4 CVEs
16.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Open Banking Iam

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.0216.85.2%14