WSO2 vendor intelligence
WSO2 Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting WSO2 products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 5
- Known exploited vulnerabilities affecting WSO2 products
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 4
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- WSO2 KEVs with sensor-observed exploitation activity
The catalog gap matters for WSO2 exposure
Four of the five exploited WSO2 CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 80% of this vendor portfolio.
- 20%
- Covered by CISA
- 80%
- Beyond CISA
- 5
- Product families
Attested WSO2 CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-5605
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure |
WSO2 Identity Server, WSO2 Enterprise Integrator, WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Manager, WSO2 API Control Plane, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, org.wso2.carbon:org.wso2.carbon.ui | High | Beyond CISA | 15 Feb 2026 |
|
CVE-2020-24589
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. |
API Manager | High | Beyond CISA | 25 Jun 2025 |
|
CVE-2024-7097
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup |
WSO2 Open Banking AM, WSO2 Open Banking KM, WSO2 Identity Server as Key Manager, WSO2 API Manager, WSO2 Identity Server, WSO2 Open Banking IAM, WSO2 Enterprise Mobility Manager | High | Beyond CISA | 30 May 2025 |
|
CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a... |
WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server Analytics, WSO2 Enterprise Integrator, WSO2 Open Banking AM, WSO2 Open Banking KM | Confirmed | In CISA | 25 Apr 2022 |
|
CVE-2020-17453
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. |
WSO2 Management Console | High | Beyond CISA | 05 Apr 2021 |
No WSO2 CVEs match this search or filter.
Showing 5 of 5 WSO2 known exploited vulnerabilities.
Recurring weakness patterns
Limitation, authentication bypass by spoofing, and restriction account for three mapped occurrences across this WSO2 KEV portfolio.
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-290
Authentication Bypass by Spoofing
CWE-611
Improper Restriction of XML External Entity Reference
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-863
Incorrect Authorization
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.