All 4 CVE vulnerabilities found in WSO2 API Control Plane, with AI-generated Chinese analysis, references, and POCs.
Vendor: WSO2
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-4103 | Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution CWE-79 | 6.4 | Medium | 2026-09-14 |
| CVE-2026-3096 | Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft CWE-20 | 4.7 | Medium | 2026-09-10 |
| CVE-2024-10302 | Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure CWE-20 | 4.0 | Medium | 2026-08-06 |
| CVE-2025-8325 | Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations CWE-281 | 6.3 | Medium | 2026-05-11 |
All 4 known CVE vulnerabilities affecting WSO2 API Control Plane with full Chinese analysis, references, and POCs where available.