📦 Api Manager

by Wso2

🔍 What is Api Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-9312

CRITICAL CVSS 9.8 Nov 18, 2025

A missing authentication enforcement vulnerability in WSO2 products allows unauthenticated access to System REST APIs and SOAP services when mutual TLS (mTLS) is enabled in certain default configurati...

CVE-2025-9152

CRITICAL CVSS 9.8 Oct 16, 2025

This vulnerability allows unauthenticated attackers to generate administrative access tokens in WSO2 API Manager by exploiting missing authentication/authorization checks in the Dynamic Client Registr...

CVE-2025-10611

CRITICAL CVSS 9.8 Oct 16, 2025

This critical vulnerability in WSO2 products allows attackers to bypass authentication and authorization checks for certain REST APIs, enabling unauthenticated administrative access. Attackers could p...

CVE-2024-6914

CRITICAL CVSS 9.8 May 22, 2025

This vulnerability allows attackers to reset any user's password via a flawed SOAP admin service in WSO2 products, leading to complete account takeover including privileged accounts. It affects WSO2 p...

CVE-2025-2905

CRITICAL CVSS 9.1 May 5, 2025

This CVE describes an XML External Entity (XXE) vulnerability in multiple WSO2 products due to improper XML parser configuration. It allows remote unauthenticated attackers to read sensitive server fi...

CVE-2021-42646

CRITICAL CVSS 9.1 May 11, 2022

This CVE describes an XML External Entity (XXE) vulnerability in WSO2 API Manager and Identity Server management consoles. Attackers can exploit it via crafted GET requests to read sensitive files fro...

CVE-2022-29464

CRITICAL CVSS 9.8 Apr 18, 2022

CVE-2022-29464 is a critical unrestricted file upload vulnerability in multiple WSO2 products that allows attackers to upload malicious files to web-accessible directories via directory traversal. Thi...

CVE-2024-1524

HIGH CVSS 7.7 Feb 24, 2026

This vulnerability allows a malicious actor to take over local user accounts when federated authentication with Silent Just-In-Time Provisioning is enabled. An attacker can associate a targeted local ...

CVE-2025-6670

HIGH CVSS 8.8 Nov 18, 2025

This CSRF vulnerability in WSO2 products allows attackers to trick authenticated users into performing unintended administrative actions by clicking malicious links. It affects WSO2 products with expo...

CVE-2025-11093

HIGH CVSS 8.4 Nov 5, 2025

This CVE describes an arbitrary code execution vulnerability in WSO2 integration products where authenticated users with elevated privileges (administrators in WSO2 Micro/Enterprise Integrator, admini...

CVE-2025-10907

HIGH CVSS 8.4 Nov 5, 2025

An arbitrary file upload vulnerability in WSO2 products allows authenticated administrators to upload malicious files to user-controlled locations via SOAP admin services. This can lead to remote code...

CVE-2023-6837

HIGH CVSS 8.5 Dec 15, 2023

This vulnerability in WSO2 products allows attackers to impersonate legitimate users through JIT provisioning flaws. Organizations using WSO2 products with specific federated authentication configurat...

CVE-2025-10713

MEDIUM CVSS 6.5 Nov 5, 2025

An XML External Entity (XXE) vulnerability in multiple WSO2 products allows attackers to read sensitive server files or cause denial-of-service. The vulnerability affects unauthenticated remote attack...

CVE-2025-3125

MEDIUM CVSS 6.7 Nov 5, 2025

An arbitrary file upload vulnerability in WSO2 products allows authenticated admin users to upload malicious files to server locations they control, potentially leading to remote code execution. This ...

CVE-2025-5605

MEDIUM CVSS 4.3 Oct 24, 2025

An authentication bypass vulnerability in WSO2 Management Console allows attackers with console access to manipulate request URIs and access restricted resources, leading to partial information disclo...

CVE-2025-5350

MEDIUM CVSS 5.9 Oct 24, 2025

This vulnerability allows attackers to perform SSRF attacks and execute reflected XSS in WSO2 products through the deprecated Try-It feature. Only administrative users are affected, as exploitation re...

CVE-2024-6429

MEDIUM CVSS 4.3 Sep 23, 2025

This content spoofing vulnerability in WSO2 products allows attackers to inject arbitrary content into error messages displayed in the browser UI. By manipulating URL parameters, malicious actors can ...

CVE-2025-5717

MEDIUM CVSS 6.8 Sep 23, 2025

This CVE describes an authenticated remote code execution vulnerability in WSO2 products where administrators can deploy malicious Java code through Siddhi execution plans. The vulnerability allows au...

CVE-2024-4598

MEDIUM CVSS 6.5 Sep 23, 2025

This CVE describes an information disclosure vulnerability in WSO2 products where authenticated users can access sensitive business data from other mediation contexts due to improper state isolation i...

CVE-2024-3511

MEDIUM CVSS 4.3 Jun 23, 2025

This CVE describes an authorization bypass vulnerability in WSO2 products that allows authenticated users with management console access to retrieve versioned registry files without proper permissions...

CVE-2024-8008

MEDIUM CVSS 5.2 Jun 2, 2025

A reflected XSS vulnerability in WSO2 products allows attackers to inject malicious JavaScript via JDBC user store connection validation error messages. This affects users of vulnerable WSO2 products,...

CVE-2024-1440

MEDIUM CVSS 5.4 Jun 2, 2025

An open redirection vulnerability in WSO2 products allows attackers to craft malicious authentication links that redirect users to attacker-controlled sites. This affects WSO2 products with multi-opti...

CVE-2024-7097

MEDIUM CVSS 4.3 May 30, 2025

This vulnerability allows attackers to create unauthorized user accounts in WSO2 products regardless of self-registration settings. It affects WSO2 products with SOAP admin service enabled. Attackers ...

CVE-2024-5962

MEDIUM CVSS 6.1 May 22, 2025

A reflected cross-site scripting (XSS) vulnerability in WSO2 authentication endpoints allows attackers to inject malicious JavaScript into the authentication flow. This affects users of multiple WSO2 ...

CVE-2024-2321

MEDIUM CVSS 5.6 Feb 27, 2025

This vulnerability allows attackers to bypass authorization in WSO2 products by using refresh tokens instead of access tokens to access protected APIs. Attackers who obtain an admin user's refresh tok...