Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WSO2 Identity Server — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in WSO2 Identity Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability disclosures specific to WSO2 Identity Server, categorizing security weaknesses by type and associated tags. It compiles a historical record of reported flaws affecting this identity and access management platform, covering incidents from the product's initial release through the most recent published advisories. Readers can utilize this collection to monitor the security posture of WSO2 over time, analyze the prevalence of specific weakness classes such as injection or authentication bypasses, and review the complete vulnerability history of the server implementation. The data provides a structured view of how security issues have emerged and been resolved, facilitating a deeper understanding of the software's risk profile without requiring manual navigation of disparate vendor bulletins. This overview supports security assessments, compliance reporting, and technical debt analysis for organizations deploying or evaluating WSO2 Identity Server in their infrastructure.

Vendor: WSO2

CVE ID Title CVSS Severity Published
CVE-2025-13166 Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery CWE-203 3.7 Low 2026-09-15
CVE-2025-15039 Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products CWE-693 9.4 Critical 2026-08-06
CVE-2025-13394 Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions CWE-352 5.4 Medium 2026-08-06
CVE-2025-13909 Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure CWE-200 4.3 Medium 2026-08-06
CVE-2025-12627 Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions CWE-613 2.4 Low 2026-08-06
CVE-2025-14779 Improper Access Control via Secret Type Management API in WSO2 Identity Server CWE-281 3.8 Low 2026-08-06
CVE-2025-11850 Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use] 4.3 Medium 2026-08-06
CVE-2025-8591 Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification CWE-79 6.1 Medium 2026-07-06
CVE-2025-13475 Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data Exposure CWE-288 3.5 Low 2026-07-04
CVE-2025-10470 Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability CWE-400 8.6 High 2026-05-11
CVE-2025-9973 Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover 6.4 Medium 2026-05-11
CVE-2025-10908 Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized Access CWE-863 - - 2026-05-11
CVE-2024-0391 Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery CWE-204 5.3 Medium 2026-05-11
CVE-2025-10503 Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 Identity Server CWE-79 6.1 Medium 2026-04-29
CVE-2025-12624 Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock CWE-613 6.0 Medium 2026-04-16
CVE-2025-5770 Reflected Cross-Site Scripting (XSS) in Authentication Endpoints of Multiple WSO2 Products CWE-79 6.1 Medium 2025-11-05
CVE-2025-3125 Authenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Leading to Remote Code Execution CWE-434 6.7 Medium 2025-11-05
CVE-2025-5605 Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure 4.3 Medium 2025-10-24
CVE-2025-5350 SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products CWE-918 5.9 Medium 2025-10-24
CVE-2025-1396 Username Enumeration in Multiple WSO2 Products with Multi-Attribute Login Enabled CWE-203 3.7 Low 2025-09-26
CVE-2025-0209 Reflected Cross-Site Scripting (XSS) in WSO2 Identity Server Account Registration Flow CWE-79 6.1 Medium 2025-09-23
CVE-2024-1440 Open Redirection in Multiple WSO2 Products via Multi-Option Authentication Endpoint CWE-601 5.4 Medium 2025-06-02
CVE-2024-7487 Improper Authentication in WSO2 Identity Server 7.0.0 Allows Bypass of App-Native Authentication CWE-287 5.8 Medium 2025-05-22
CVE-2024-7103 Reflected Cross-Site Scripting (XSS) in WSO2 Identity Server 7.0.0 Sub-Organization Login Flow CWE-79 4.6 Medium 2025-05-22

All 24 known CVE vulnerabilities affecting WSO2 Identity Server with full Chinese analysis, references, and POCs where available.