Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wso2 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2023-30527
Jenkins WSO2 Oauth Plugin 1.0 and previous versions stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Jenkins Wso2 Oauth
6.5
CVSSv3
CVE-2023-30528
Jenkins WSO2 Oauth Plugin 1.0 and previous versions does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for malicious users to observe and capture it.
Jenkins Wso2 Oauth
6.1
CVSSv3
CVE-2023-31664
A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager prior to 4.2.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter.
Wso2 Api Manager
1 Github repository
5.4
CVSSv3
CVE-2023-33005
Jenkins WSO2 Oauth Plugin 1.0 and previous versions does not invalidate the previous session on login.
Jenkins Wso2 Oauth
5.4
CVSSv3
CVE-2023-33006
A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and previous versions allows malicious users to trick users into logging in to the attacker's account.
Jenkins Wso2 Oauth
5.4
CVSSv3
CVE-2018-8716
WSO2 Identity Server prior to 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
Wso2 Identity Server
1 EDB exploit
7.2
CVSSv3
CVE-2020-11885
WSO2 Enterprise Integrator up to and including 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.
Wso2 Enterprise Integrator
6.1
CVSSv3
CVE-2022-4520
A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue is some unknown functionality of the file components/registry/org.wso2.carbon.registry.search.ui/src/main/resources/web/search/advancedSearchForm-ajaxprocessor...
Wso2 Carbon-registry
6.1
CVSSv3
CVE-2022-4521
A vulnerability classified as problematic has been found in WSO2 carbon-registry up to 4.8.6. This affects an unknown part of the component Request Parameter Handler. The manipulation of the argument parentPath/path/username/path/profile_menu leads to cross site scripting. It is ...
Wso2 Carbon-registry
5.4
CVSSv3
CVE-2020-25516
WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.
Wso2 Enterprise Integrator
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »