WSO2 vendor intelligence

WSO2 Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting WSO2 products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse WSO2 KEVs Full KEV feed
Total KEVs
5
Known exploited vulnerabilities affecting WSO2 products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
WSO2 KEVs with sensor-observed exploitation activity

The catalog gap matters for WSO2 exposure

Four of the five exploited WSO2 CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 80% of this vendor portfolio.

20%
Covered by CISA
80%
Beyond CISA
5
Product families

Attested WSO2 CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-5605

Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure

WSO2 Identity Server, WSO2 Enterprise Integrator, WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Manager, WSO2 API Control Plane, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, org.wso2.carbon:org.wso2.carbon.ui High Beyond CISA 15 Feb 2026
CVE-2020-24589

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

API Manager High Beyond CISA 25 Jun 2025
CVE-2024-7097

Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup

WSO2 Open Banking AM, WSO2 Open Banking KM, WSO2 Identity Server as Key Manager, WSO2 API Manager, WSO2 Identity Server, WSO2 Open Banking IAM, WSO2 Enterprise Mobility Manager High Beyond CISA 30 May 2025
CVE-2022-29464

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a...

WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server Analytics, WSO2 Enterprise Integrator, WSO2 Open Banking AM, WSO2 Open Banking KM Confirmed In CISA 25 Apr 2022
CVE-2020-17453

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

WSO2 Management Console High Beyond CISA 05 Apr 2021

Showing 5 of 5 WSO2 known exploited vulnerabilities.

Recurring weakness patterns

Limitation, authentication bypass by spoofing, and restriction account for three mapped occurrences across this WSO2 KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.