- What is the WSO2 CNA?
- WSO2 is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 45 CVE records since 2023.
- How many CVEs has WSO2 published?
- WSO2 has published 45 CVE records, including 39 in the last two years.
- What is WSO2's CVE data quality grade?
- RadicalNotion.AI grades WSO2's CVE data quality as A, with an overall completeness score of 100%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (100%), and CWE (100%) information.
- What products does WSO2 publish CVEs for?
- WSO2 most frequently publishes CVEs for WSO2 API Manager, WSO2 Identity Server, api manager, identity server, identity server as key manager.
- Which vendors does WSO2 cover?
- WSO2 publishes CVEs across 1 distinct vendors, most often WSO2, wso2-attic.
- Is WSO2 actively publishing CVEs?
- WSO2 is currently active, based on 39 CVEs in the last two years.
- What is the average severity of WSO2's CVEs?
- The average CVSS base score across WSO2's scored CVEs is 6.3.
- How many critical CVEs has WSO2 published?
- WSO2 has published 15 critical-severity CVEs and 20 high-severity CVEs.
- Are any of WSO2's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of WSO2's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in WSO2's CVEs?
- WSO2's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-863 (Incorrect Authorization), CWE-434 (Unrestricted Upload of File with Dangerous Type), CWE-611 (Improper Restriction of XML External Entity Reference).
- How does WSO2 rank among CNAs?
- By total CVE volume, WSO2 ranks #176 of 370 CNAs, and it reports more complete CVE records than 60% of all CNAs.