- How many CVEs does WSO2 have?
- WSO2 has 125 published CVE records since 2017, including 61 in the last two years.
- How many WSO2 CVEs are in CISA KEV?
- Yes — 1 of WSO2's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which WSO2 products have the most CVEs?
- The WSO2 products with the most published CVEs are api manager, identity server, product-apim, WSO2 API Manager, WSO2 Identity Server.
- What are the most common weakness types in WSO2 CVEs?
- WSO2's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-863 (Incorrect Authorization), CWE-611 (Improper Restriction of XML External Entity Reference), CWE-434 (Unrestricted Upload of File with Dangerous Type).
- Are there public exploits for WSO2 vulnerabilities?
- Yes — 14 of WSO2's CVEs have a known public exploit.
- How many critical WSO2 vulnerabilities are there?
- WSO2 has 15 critical and 24 high-severity CVEs.
- What is the average severity of WSO2 CVEs?
- The average CVSS base score across WSO2's scored CVEs is 6.5.