CVE Tools

WSO2

110 CVEs tracked since 2017. Since Feb 2017, none of them reached CISA KEV.

WSO2 CVEs per month

Feb 2017 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
WSO2 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0260
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-0550
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01100
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0640
2020-07null or fewer
2020-0870
2020-09null or fewer
2020-1030
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-1260
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-0570
2025-0660
2025-07null or fewer
2025-08null or fewer
2025-0990
2025-1060
2025-1180
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0470
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-08190
2026-0970

Products

The products that kept showing up in WSO2's monthly top three, with their CVEs summed over those months.

  1. API Manager519 months
  2. WSO2 API Manager487 months
  3. WSO2 Identity Server315 months
  4. Identity Server266 months
  5. API Control Plane132 months
  6. Identity Server As Key Manager133 months
  7. WSO2 Universal Gateway111 month
  8. API Manager Analytics51 month
  9. Identity Server Analytics51 month
  10. WSO2 API Control Plane51 month

Latest CVEs

The 15 most recently published vulnerabilities affecting WSO2.

  1. CVE-2025-13166Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery3.7
  2. CVE-2025-5802Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery5.3
  3. CVE-2026-19515OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution7.0
  4. CVE-2026-4103Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution6.4
  5. CVE-2026-3096Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft4.7
  6. CVE-2025-12737Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution8.4
  7. CVE-2026-3416Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads5.9
  8. CVE-2026-3418Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution9.1
  9. CVE-2026-3415XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service8.7
  10. CVE-2025-14561Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations9.0
  11. CVE-2025-12317Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges5.0
  12. CVE-2025-6508User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows Sensitive Information Exposure or Unintended Requests4.3
  13. CVE-2024-6541Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products6.8
  14. CVE-2026-5430Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover10.0
  15. CVE-2026-1728Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover9.8

The record

Peak rank
#43 in Feb 2017
Busiest month shown
Aug 2026, 19 CVEs
Months with a KEV entry
0 since Feb 2017
Monthly snapshots
15 since 2017
WSO2's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store