Vulnerabilities in WSO2

95 results
Vexday analysis

Com 63 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o WSO2 apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica menor pressão imediata de ameaças confirmadas em campo. No entanto, 7 vulnerabilidades de severidade crítica e 13 surgidas nos últimos 90 dias sinalizam um ritmo de descoberta que exige monitoramento contínuo. A falha mais comum é CWE-79 (Cross-site Scripting), padrão que, embora frequentemente subestimado, pode viabilizar ataques de sequestro de sessão e roubo de credenciais em plataformas de integração como as oferecidas pelo vendor. A CVE mais perigosa ativa no momento, CVE-2024-7074, registra escore EPSS de 0,0976 — probabilidade ainda moderada de exploração iminente, mas suficiente para recomendar priorização no ciclo de patching das equipes responsáveis por ambientes WSO2.

CVE-2024-1248MEDIUMRole Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege EscalationEPSS 0.3%CVE-2025-13475LOWCross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data ExposureEPSS 0.3%CVE-2024-8010LOWXML External Entity Injection via Publisher in WSO2 API Manager Allows Reading Arbitrary FilesEPSS 0.3%CVE-2024-1524HIGHA local user can be impersonated when using federated authentication with Silent JIT Provisioning.EPSS 0.3%CVE-2026-3416MEDIUMPredictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event PayloadsEPSS 0.3%CVE-2024-6541MEDIUMInformation Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 ProductsEPSS 0.3%CVE-2026-2445MEDIUMReflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and ModificationEPSS 0.3%CVE-2025-8591MEDIUMReflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI ModificationEPSS 0.3%CVE-2024-5962MEDIUMReflected Cross-Site Scripting (XSS) in Authentication Endpoint of Multiple WSO2 Products Due to Missing Output EncodingEPSS 0.3%CVE-2025-1396LOWUsername Enumeration in Multiple WSO2 Products with Multi-Attribute Login EnabledEPSS 0.3%CVE-2025-5802MEDIUMUsername Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account DiscoveryEPSS 0.3%CVE-2024-2321MEDIUMIncorrect Authorization in Multiple WSO2 Products Allows API Access via Refresh TokenEPSS 0.2%CVE-2024-6832MEDIUMAccount Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force AttacksEPSS 0.2%CVE-2025-0663MEDIUMPotential cross-tenant account takeover vulnerability in Multiple WSO2 Products via Adaptive Authentication and Auto-LoginEPSS 0.2%CVE-2025-12317MEDIUMImproper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access PrivilegesEPSS 0.2%CVE-2024-10242MEDIUMReflected Cross-Site Scripting via Authentication Endpoint in WSO2 API Manager Allows UI Modification and RedirectionEPSS 0.2%CVE-2025-9312CRITICALImproper Certificate-Based Authentication Enforcement in Multiple WSO2 ProductsEPSS 0.2%CVE-2024-5848MEDIUMReflected Cross-Site Scripting (XSS) in Multiple WSO2 Products Due to Improper Input ValidationEPSS 0.2%CVE-2025-6670HIGHCross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin ServicesEPSS 0.2%CVE-2025-0209MEDIUMReflected Cross-Site Scripting (XSS) in WSO2 Identity Server Account Registration FlowEPSS 0.2%