Universal Gateway
Vendor:
First CVE: Sep 23, 2025 · Active for under a year
17
Total CVEs
More Total CVEs than 94% of tracked products
8.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Universal Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2025
10 months ago
Most Recent CVE
Jul 6, 2026
22 days ago
CVE Severity & Scoring
Universal Gateway17 CVEs
35%
47%
18%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (70.6%)
Unknown0 (0.0%)
Required5 (29.4%)
Privileges Required
Low2 (11.8%)
High6 (35.3%)
None9 (52.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4249HIGH The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an u | Jul 6, 2026 | 8.6 | 36 | NO | NO |
CVE-2025-5605MEDIUM An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to by | Oct 24, 2025 | 5.3 | 34 | NO | YES |
CVE-2025-10611CRITICAL Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be i | Oct 16, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-8325HIGH The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended perm | May 11, 2026 | 8.8 | 32 | NO | NO |
CVE-2025-9312CRITICAL A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to impro | Nov 18, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-8154HIGH In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected | May 11, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-13590HIGH A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead | Feb 19, 2026 | 7.2 | 29 | NO | NO |
CVE-2025-5350MEDIUM SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepte | Oct 24, 2025 | 4.8 | 29 | NO | YES |
CVE-2025-8591MEDIUM The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to | Jul 6, 2026 | 6.1 | 28 | NO | NO |
CVE-2025-10713CRITICAL An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applyi | Nov 5, 2025 | 9.1 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
11.8% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Universal Gateway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.6.0 | 2 | 8.0 | 0.4% | 0 | 0 |
| 4.5.0 | 12 | 7.2 | 0.5% | 0 | 2 |