WSO2 Identity Server
3 known vulnerabilities in WSO2 Identity Server, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2025-5802 CVSS 5.3 medium The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence…
- CVE-2025-13166 CVSS 3.7 low The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based…
- CVE-2025-12737 CVSS 8.4 high The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a…