Vulnerabilities (CVE)

Filtered by vendor Wso2 Subscribe
Filtered by product Identity Server
Total 63 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-18881 1 Wso2 1 Identity Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
CVE-2018-8716 1 Wso2 1 Identity Server 2024-11-21 3.5 LOW 5.4 MEDIUM
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
CVE-2018-20737 1 Wso2 3 Api Manager, Identity Server, Identity Server As Key Manager 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.