VYPR

Wso2

by GitHub

CVEs (2)

  • CVE-2026-1728CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full…

  • CVE-2024-2374HigApr 16, 2026
    risk 0.49cvss 7.5epss 0.00

    The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of…