
WSO2 identity server Vulnerabilities
CVE security advisories and vulnerability history for identity server by WSO2.
Last updated

CVE security advisories and vulnerability history for identity server by WSO2.
Last updated
WSO2 identity server has 83 published CVE records since 2017, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 17 have a known public exploit. The average CVSS base score across scored CVEs is 6.4.
This page aggregates every publicly disclosed vulnerability (CVE) affecting WSO2 identity server, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
How the CVSS severity of WSO2 identity server's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of WSO2 identity server's CVEs is confirmed exploited in the wild.
Public exploits
17
17 of WSO2 identity server's CVEs have a known public exploit available.
Browse every WSO2 identity server version named in a CVE, then pick one to see only the CVEs that affect it.
83 CVEs
Showing 30 of 83
The CWE weakness categories most often found in WSO2 identity server CVEs. Follow any weakness for its full explanation.
How many WSO2 identity server CVEs were published each year.
Browse vulnerabilities for other products by WSO2.
Common questions about WSO2 identity server vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new WSO2 identity server vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.