Vulnerabilities > Wso2 > Enterprise Integrator

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-6911 Cross-site Scripting vulnerability in Wso2 products
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
network
low complexity
wso2 CWE-79
4.8
2023-12-15 CVE-2023-6836 XXE vulnerability in Wso2 products
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
network
low complexity
wso2 CWE-611
7.5
2022-09-09 CVE-2022-39809 Cross-site Scripting vulnerability in Wso2 Enterprise Integrator 6.4.0
An issue was discovered in WSO2 Enterprise Integrator 6.4.0.
network
low complexity
wso2 CWE-79
6.1
2022-09-09 CVE-2022-39810 Cross-site Scripting vulnerability in Wso2 Enterprise Integrator 6.4.0
An issue was discovered in WSO2 Enterprise Integrator 6.4.0.
network
low complexity
wso2 CWE-79
6.1
2022-04-21 CVE-2022-29548 Cross-site Scripting vulnerability in Wso2 products
A reflected XSS issue exists in the Management Console of several WSO2 products.
network
low complexity
wso2 CWE-79
6.1
2022-04-18 CVE-2022-29464 Path Traversal vulnerability in Wso2 products
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
network
low complexity
wso2 CWE-22
critical
9.8
2021-04-05 CVE-2020-17453 Cross-site Scripting vulnerability in Wso2 products
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
network
low complexity
wso2 CWE-79
6.1
2020-10-29 CVE-2020-25516 Cross-site Scripting vulnerability in Wso2 Enterprise Integrator
WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.
network
low complexity
wso2 CWE-79
5.4
2020-08-27 CVE-2020-24704 Cross-site Scripting vulnerability in Wso2 products
An issue was discovered in certain WSO2 products.
network
low complexity
wso2 CWE-79
6.1
2020-08-27 CVE-2020-24703 Unspecified vulnerability in Wso2 products
An issue was discovered in certain WSO2 products.
network
low complexity
wso2
8.8