WSO2 API Manager
6 known vulnerabilities in WSO2 API Manager, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-5430 CVSS 10.0 critical · actively exploited WSO2 Multiple Products Path Traversal Vulnerability
Latest vulnerabilities
- CVE-2025-5802 CVSS 5.3 medium The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence…
- CVE-2026-4103 CVSS 6.4 medium Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper…
- CVE-2026-3096 CVSS 4.7 medium The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window…
- CVE-2025-12737 CVSS 8.4 high The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a…
- CVE-2026-3416 CVSS 7.5 high The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook…
- CVE-2026-5430 CVSS 10.0 critical · actively exploited WSO2 Multiple Products Path Traversal Vulnerability