{"api_version":"v1","generated_at":"2026-10-09T07:55:00+00:00","product":{"cve_count":25,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-wso2-wso2-identity-server-433cad0ffc50","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"WSO2 Identity Server","next_cursor":null,"observations":[{"affected":"WSO2 Identity Server: < 5.11.0, 5.11.0 < 5.11.0.372, 6.0.0 < 6.0.0.227, 6.1.0 < 6.1.0.219","affected_versions_present":true,"cve_id":"CVE-2024-8122","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-8122","fixed":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3149/#solution","last_modified":"2026-10-08T17:13:45.357Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3149/","primary_source":"","published":"2026-10-08T00:09:52.353Z"},{"affected":"WSO2 Identity Server: 7.1.0 < 7.1.0.40, 7.2.0 < 7.2.0.2","affected_versions_present":true,"cve_id":"CVE-2025-13166","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-13166","fixed":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4353/#solution","last_modified":"2026-09-15T22:15:37.413Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4353/","primary_source":"","published":"2026-09-15T09:53:54.532Z"},{"affected":"WSO2 Identity Server: < 5.7.0, 5.7.0 < 5.7.0.130, 5.8.0 < 5.8.0.113, 5.9.0 < 5.9.0.173, 5.10.0 < 5.10.0.385, 5.11.0 < 5.11.0.432, 6.0.0 < 6.0.0.259, 6.1.0 < 6.1.0.260, 7.0.0 < 7.0.0.138, 7.1.0 < 7.1.0.45, 7.1.0 < 7.1.0.49, 7.2.0 < 7.2.0.7; WSO2 API Manager: < 2.6.0, 2.6.0 < 2.6.0.150, 3.0.0 < 3.0.0.180, 3.1.0 < 3.1.0.356, 3.2.0 < 3.2.0.460, 3.2.1 < 3.2.1.79, 4.0.0 < 4.0.0.381, 4.1.0 < 4.1.0.244, 4.2.0 < 4.2.0.184, 4.3.0 < 4.3.0.95, 4.4.0 < 4.4.0.59, 4.5.0 < 4.5.0.44, 4.6.0 < 4.6.0.8; WSO2 Open Banking AM: < 1.4.0, 1.4.0 < 1.4.0.143, 1.5.0 < 1.5.0.144, 2.0.0 < 2.0.0.405; WSO2 Open Banking IAM: < 2.0.0, 2.0.0 < 2.0.0.425; WSO2 Traffic Manager: < 4.5.0, 4.5.0 < 4.5.0.43, 4.6.0 < 4.6.0.8; WSO2 Universal Gateway: 4.5.0 < 4.5.0.43, 4.5.0 < 4.5.0.44, 4.6.0 < 4.6.0.8; WSO2 API Control Plane: 4.5.0 < 4.5.0.45, 4.6.0 < 4.6.0.9; WSO2 Identity Server as Key Manager: < 5.7.0, 5.7.0 < 5.7.0.129, 5.9.0 < 5.9.0.179, 5.10.0 < 5.10.0.376; WSO2 Open Banking KM: < 1.4.0, 1.4.0 < 1.4.0.137, 1.5.0 < 1.5.0.127; WSO2 Carbon Identity Application Authentication Framework: 5.12.153 < 5.12.153.66, 5.12.387 < 5.12.387.48, 5.14.97 < 5.14.97.94, 5.17.5 < 5.17.5.337, 5.17.118 < 5.17.118.24, 5.18.187 < 5.18.187.334, 5.18.248 < 5.18.248.34, 5.23.8 < 5.23.8.221, 5.24.8 < 5.24.8.29, 5.25.92 < 5.25.92.177, 5.25.705 < 5.25.705.23, 5.25.713 < 5.25.713.12, 5.25.724 < 5.25.724.8, 5.25.736 < 5.25.736.3, 7.0.78 < 7.0.78.171, 7.8.23 < 7.8.23.95, 7.8.586 < 7.8.586.21","affected_versions_present":true,"cve_id":"CVE-2025-15039","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-15039","fixed":"WSO2 Carbon Identity Application Authentication Framework: 5.25.738 \u2264 5.25.*, 7.8.646 \u2264 *","last_modified":"2026-08-06T12:31:43.779Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/","primary_source":"","published":"2026-08-06T07:33:23.097Z"},{"affected":"WSO2 Identity Server: < 5.10.0, 5.10.0 < 5.10.0.381, 5.11.0 < 5.11.0.428, 6.0.0 < 6.0.0.255, 6.1.0 < 6.1.0.256, 7.0.0 < 7.0.0.133, 7.1.0 < 7.1.0.41, 7.2.0 < 7.2.0.3; WSO2 API Manager: < 3.1.0, 3.1.0 < 3.1.0.352, 3.2.0 < 3.2.0.456, 3.2.1 < 3.2.1.75, 4.0.0 < 4.0.0.376, 4.1.0 < 4.1.0.239, 4.2.0 < 4.2.0.179, 4.3.0 < 4.3.0.91, 4.4.0 < 4.4.0.55, 4.5.0 < 4.5.0.38, 4.6.0 < 4.6.0.3; WSO2 Open Banking IAM: < 2.0.0, 2.0.0 < 2.0.0.421; WSO2 Open Banking AM: < 2.0.0, 2.0.0 < 2.0.0.401; WSO2 Identity Server as Key Manager: < 5.10.0, 5.10.0 < 5.10.0.372; WSO2 API Control Plane: < 4.5.0, 4.5.0 < 4.5.0.39, 4.6.0 < 4.6.0.3; WSO2 Universal Gateway: < 4.5.0, 4.5.0 < 4.5.0.37, 4.6.0 < 4.6.0.3; WSO2 Traffic Manager: < 4.5.0, 4.5.0 < 4.5.0.37, 4.6.0 < 4.6.0.3; WSO2 Enterprise Integrator: < 6.6.0, 6.6.0 < 6.6.0.227; WSO2 Carbon Identity Entitlement UI: 5.17.5 < 5.17.5.331, 5.18.187 < 5.18.187.329, 5.23.8 < 5.23.8.210, 5.25.92 < 5.25.92.166, 7.0.78 < 7.0.78.157; WSO2 Carbon Identity Management UI1: 5.17.5 < 5.17.5.330, 5.17.5 < 5.17.5.331, 5.17.118 < 5.17.118.22, 5.18.187 < 5.18.187.328, 5.18.187 < 5.18.187.329, 5.18.248 < 5.18.248.31, 5.23.8 < 5.23.8.210, 5.24.8 < 5.24.8.26, 5.25.92 < 5.25.92.166, 5.25.705 < 5.25.705.21, 5.25.713 < 5.25.713.10, 5.25.724 < 5.25.724.5, 5.25.736 < 5.25.736.1, 7.0.78 < 7.0.78.157, 7.8.23 < 7.8.23.67, 7.8.586 < 7.8.586.7; WSO2 Carbon Identity User Store Configuration UI: 5.14.127 < 5.14.127.13, 5.17.5 < 5.17.5.330, 5.17.5 < 5.17.5.331, 5.17.118 < 5.17.118.22, 5.18.187 < 5.18.187.328, 5.18.187 < 5.18.187.329, 5.18.248 < 5.18.248.31, 5.23.8 < 5.23.8.210, 5.24.8 < 5.24.8.26, 5.25.92 < 5.25.92.166, 5.25.705 < 5.25.705.21, 5.25.713 < 5.25.713.10, 5.25.724 < 5.25.724.5, 5.25.736 < 5.25.736.1, 7.0.78 < 7.0.78.157, 7.8.23 < 7.8.23.67, 7.8.586 < 7.8.586.7; WSO2 Carbon Registry Profiles UI: 4.7.32 < 4.7.32.18, 4.7.33 < 4.7.33.16, 4.8.9 < 4.8.9.16, 4.8.12 < 4.8.12.8, 4.8.24 < 4.8.24.6, 4.8.43 < 4.8.43.4, 4.8.50 < 4.8.50.3; WSO2 Carbon Registry Properties UI: 4.7.24 < 4.7.24.11, 4.7.32 < 4.7.32.16, 4.7.32 < 4.7.32.18, 4.7.33 < 4.7.33.16, 4.7.35 < 4.7.35.15, 4.7.39 < 4.7.39.12, 4.7.51 < 4.7.51.8, 4.8.3 < 4.8.3.10, 4.8.9 < 4.8.9.16, 4.8.12 < 4.8.12.8, 4.8.13 < 4.8.13.9, 4.8.24 < 4.8.24.6, 4.8.32 < 4.8.32.4, 4.8.36 < 4.8.36.2, 4.8.43 < 4.8.43.2, 4.8.43 < 4.8.43.4, 4.8.50 < 4.8.50.1, 4.8.50 < 4.8.50.3; WSO2 Carbon Registry Resources UI: 4.7.24 < 4.7.24.11, 4.7.32 < 4.7.32.16, 4.7.32 < 4.7.32.18, 4.7.33 < 4.7.33.16, 4.7.35 < 4.7.35.15, 4.7.39 < 4.7.39.12, 4.7.51 < 4.7.51.8, 4.8.3 < 4.8.3.10, 4.8.9 < 4.8.9.16, 4.8.12 < 4.8.12.8, 4.8.13 < 4.8.13.9, 4.8.24 < 4.8.24.6, 4.8.32 < 4.8.32.4, 4.8.36 < 4.8.36.2, 4.8.43 < 4.8.43.2, 4.8.43 < 4.8.43.4, 4.8.50 < 4.8.50.1, 4.8.50 < 4.8.50.3; WSO2 Carbon Registry Search UI: 4.7.24 < 4.7.24.11, 4.7.32 < 4.7.32.16, 4.7.32 < 4.7.32.18, 4.7.33 < 4.7.33.16, 4.7.35 < 4.7.35.15, 4.7.39 < 4.7.39.12, 4.7.51 < 4.7.51.8, 4.8.3 < 4.8.3.10, 4.8.9 < 4.8.9.16, 4.8.12 < 4.8.12.8, 4.8.13 < 4.8.13.9, 4.8.24 < 4.8.24.6; WSO2 Stratos User Interface For Tenant CRUD Operations: 4.8.1 < 4.8.1.6, 4.8.7 < 4.8.7.3, 4.9.8 < 4.9.8.7, 4.9.10 < 4.9.10.7, 4.9.10 < 4.9.10.8, 4.9.20 < 4.9.20.5, 4.9.27 < 4.9.27.1, 4.9.31 < 4.9.31.1, 4.9.34 < 4.9.34.1, 4.9.42 < 4.9.42.1, 4.11.0 < 4.11.0.7, 4.11.19 < 4.11.19.4, 4.11.34 < 4.11.34.3, 4.11.45 < 4.11.45.1; WSO2 Stratos SSO Redirector UI Component: 4.8.1 < 4.8.1.6; WSO2 Carbon Email Verification UI: 4.7.19 < 4.7.19.14; WSO2 Carbon Event Simulator UI: 2.2.11 < 2.2.11.1, 2.2.14 < 2.2.14.11, 2.2.14 < 2.2.14.12, 2.2.17 < 2.2.17.5, 2.3.1 < 2.3.1.4, 2.3.5 < 2.3.5.6; WSO2 Carbon Execution Manager UI: 5.2.24 < 5.2.24.10, 5.2.26 < 5.2.26.22, 5.2.34 < 5.2.34.12, 5.2.41 < 5.2.41.7, 5.2.57 < 5.2.57.10, 5.3.5 < 5.3.5.9; WSO2 Carbon Governance Custom Lifecycle Checklist UI: 4.8.14 < 4.8.14.4, 4.8.19 < 4.8.19.8, 4.8.21 < 4.8.21.10, 4.8.28 < 4.8.28.4, 4.8.30 < 4.8.30.6, 4.8.32 < 4.8.32.4; 25 additional product groups retained in the authoritative source","affected_versions_present":true,"cve_id":"CVE-2025-13394","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-13394","fixed":"WSO2 Carbon Identity Entitlement UI: x \u2264 *; WSO2 Carbon Identity Management UI1: x \u2264 *; WSO2 Carbon Identity User Store Configuration UI: x \u2264 *; WSO2 Carbon Registry Profiles UI: x \u2264 *; WSO2 Carbon Registry Properties UI: x \u2264 *; WSO2 Carbon Registry Resources UI: x \u2264 *; WSO2 Carbon Registry Search UI: x \u2264 *; WSO2 Stratos User Interface For Tenant CRUD Operations: x \u2264 *; WSO2 Stratos SSO Redirector UI Component: x \u2264 *; WSO2 Carbon Email Verification UI: x \u2264 *; WSO2 Carbon Event Simulator UI: x \u2264 *; WSO2 Carbon Execution Manager UI: x \u2264 *; WSO2 Carbon Governance Custom Lifecycle Checklist UI: x \u2264 *; WSO2 Carbon Governance Generic Artifact User Interface: x \u2264 *; WSO2 Carbon Governance Life Cycles User Interface: x \u2264 *; WSO2 Carbon Governance WSDL Tool UI: x \u2264 *; WSO2 Carbon New Data Sources UI: x \u2264 *; WSO2 Carbon Registry Info UI2: x \u2264 *; WSO2 Carbon Registry Relations UI: x \u2264 *; WSO2 Carbon Registry Indexing: x \u2264 *; WSO2 Carbon Security UI: x \u2264 *; WSO2 Carbon Component Andes Event UI: x \u2264 *; WSO2 Carbon Component Andes UI1: x \u2264 *; WSO2 Carbon HL7 Business Messaging Store UI: x \u2264 *; WSO2 Carbon Endpoint Editor UI: x \u2264 *; WSO2 Carbon Publish Event Mediator Configuration UI: x \u2264 *; WSO2 Carbon Eventing UI: x \u2264 *; WSO2 Carbon HumanTask UI: x \u2264 *; WSO2 Carbon Logging UI: x \u2264 *; WSO2 Carbon Template Editor UI: x \u2264 *; WSO2 Carbon Command Mediator UI: x \u2264 *; WSO2 Carbon Rule Mediator UI: x \u2264 *; WSO2 Carbon Throttle Mediator UI: x \u2264 *; WSO2 Carbon Tasks Core: x \u2264 *; WSO2 Carbon Rest API Admin UI: x \u2264 *; WSO2 Carbon Sequence Editor UI: x \u2264 *; WSO2 Carbon Task UI: x \u2264 *; WSO2 Carbon Governance: x \u2264 *","last_modified":"2026-08-06T12:32:29.065Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4800/","primary_source":"","published":"2026-08-06T07:33:17.645Z"},{"affected":"WSO2 Identity Server: 7.0.0 < 7.0.0.134, 7.1.0 < 7.1.0.42; WSO2 Carbon Identity Application Authentication Framework: 7.0.78 < 7.0.78.162, 7.8.23 < 7.8.23.66; WSO2 Carbon MagicLink Authenticator Module: 1.1.22 < 1.1.22.6, 1.1.31 < 1.1.31.3; WSO2 Carbon Abstract OTP Authenticator: 1.0.5 < 1.0.5.4, 1.0.10 < 1.0.10.1; Email OTP Authenticator: 1.0.30 < 1.0.30.4","affected_versions_present":true,"cve_id":"CVE-2025-13909","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-13909","fixed":"WSO2 Carbon Identity Application Authentication Framework: 7.8.550 \u2264 *; WSO2 Carbon MagicLink Authenticator Module: 1.1.45 \u2264 *; WSO2 Carbon Abstract OTP Authenticator: 1.0.24 \u2264 *; Email OTP Authenticator: 1.0.51 \u2264 *","last_modified":"2026-08-06T12:33:19.505Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4731/","primary_source":"","published":"2026-08-06T07:33:14.712Z"},{"affected":"WSO2 Identity Server: 7.0.0 < 7.0.0.130, 7.1.0 < 7.1.0.38; WSO2 Carbon OAuth: 7.0.26 < 7.0.26.83, 7.0.259 < 7.0.259.31","affected_versions_present":true,"cve_id":"CVE-2025-12627","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-12627","fixed":"WSO2 Carbon OAuth: x \u2264 *","last_modified":"2026-08-06T12:33:46.393Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4619/","primary_source":"","published":"2026-08-06T07:33:12.382Z"},{"affected":"WSO2 Identity Server: 6.0.0 < 6.0.0.261, 6.1.0 < 6.1.0.262, 7.1.0 < 7.1.0.46; WSO2 Carbon Identity API Server Secret Management Common: 1.2.3 < 1.2.3.7, 1.2.23 < 1.2.23.11, 1.3.83 < 1.3.83.16; WSO2 Carbon Identity API Server Secret Management V1: 1.2.3 < 1.2.3.7, 1.2.23 < 1.2.23.11, 1.3.83 < 1.3.83.16","affected_versions_present":true,"cve_id":"CVE-2025-14779","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-14779","fixed":"WSO2 Carbon Identity API Server Secret Management Common: 7.8.521 \u2264 *; WSO2 Carbon Identity API Server Secret Management V1: 7.8.521 \u2264 *","last_modified":"2026-08-06T12:35:21.870Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4597/","primary_source":"","published":"2026-08-06T07:33:10.018Z"},{"affected":"WSO2 Identity Server: 7.0.0 < 7.0.0.132, 7.1.0 < 7.1.0.40","affected_versions_present":true,"cve_id":"CVE-2025-11850","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-11850","fixed":"Token Exchange Grant Type For OAuth: 1.1.19 \u2264 *","last_modified":"2026-08-06T12:36:25.111Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4493/","primary_source":"","published":"2026-08-06T07:33:07.471Z"},{"affected":"WSO2 Identity Server: < 5.10.0, 5.10.0 < 5.10.0.381, 5.10.0 < 5.10.0.384, 6.0.0 < 6.0.0.255, 7.0.0 < 7.0.0.131, 7.1.0 < 7.1.0.21, 7.1.0 < 7.1.0.51; WSO2 API Manager: < 3.1.0, 3.1.0 < 3.1.0.355, 3.2.0 < 3.2.0.459, 3.2.1 < 3.2.1.78, 4.0.0 < 4.0.0.380, 4.1.0 < 4.1.0.243, 4.2.0 < 4.2.0.183, 4.3.0 < 4.3.0.94, 4.4.0 < 4.4.0.58, 4.5.0 < 4.5.0.43, 4.6.0 < 4.6.0.7; WSO2 API Control Plane: 4.5.0 < 4.5.0.44, 4.6.0 < 4.6.0.8; WSO2 Traffic Manager: 4.5.0 < 4.5.0.42, 4.6.0 < 4.6.0.7; WSO2 Universal Gateway: 4.5.0 < 4.5.0.42, 4.6.0 < 4.6.0.7; WSO2 Open Banking AM: < 2.0.0, 2.0.0 < 2.0.0.404; WSO2 Identity Server as Key Manager: < 5.10.0, 5.10.0 < 5.10.0.375; WSO2 Open Banking IAM: < 2.0.0, 2.0.0 < 2.0.0.424","affected_versions_present":true,"cve_id":"CVE-2025-8591","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-8591","fixed":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4343/#solution","last_modified":"2026-07-06T11:05:59.157Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4343/","primary_source":"","published":"2026-07-06T10:16:53.685Z"},{"affected":"WSO2 Identity Server: < 5.10.0, 5.10.0 < 5.10.0.382; WSO2 API Manager: < 3.2.0, 3.2.0 < 3.2.0.457, 3.2.1 < 3.2.1.76","affected_versions_present":true,"cve_id":"CVE-2025-13475","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-13475","fixed":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-1613/#solution","last_modified":"2026-07-06T13:55:26.159Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-1613/","primary_source":"","published":"2026-07-04T12:49:06.782Z"},{"affected":"7.0.0 < 7.0.0.121; 1.1.22 < 1.1.22.3","affected_versions_present":true,"cve_id":"CVE-2025-10470","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10470","fixed":"1.1.31 \u2264 *","last_modified":"2026-05-11T12:38:39.383Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4469/","primary_source":"","published":"2026-05-11T10:16:52.358Z"},{"affected":"7.1.0 < 7.1.0.26; 1.2.76 < 1.2.76.1","affected_versions_present":true,"cve_id":"CVE-2025-9973","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-9973","fixed":"1.2.82 \u2264 *","last_modified":"2026-05-11T15:18:59.783Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4530/","primary_source":"","published":"2026-05-11T10:12:39.547Z"},{"affected":"< 6.0.0; 6.0.0 < 6.0.0.249; 6.1.0 < 6.1.0.248; 7.0.0 < 7.0.0.124; 7.1.0 < 7.1.0.31; 1.1.0 < 1.1.0.1; 1.1.5 < 1.1.5.2; 1.1.22 < 1.1.22.5","affected_versions_present":true,"cve_id":"CVE-2025-10908","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10908","fixed":"1.1.43 \u2264 *","last_modified":"2026-05-11T18:38:02.953Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4388/","primary_source":"","published":"2026-05-11T09:01:43.938Z"},{"affected":"< 5.10.0; 5.10.0 < 5.10.0.379; 5.11.0 < 5.11.0.426; 5.11.0 < 5.11.0.431; 6.0.0 < 6.0.0.253; 6.1.0 < 6.1.0.254; 7.0.0 < 7.0.0.131; < 2.0.0","affected_versions_present":true,"cve_id":"CVE-2024-0391","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-0391","fixed":"1.0.24 \u2264 *; 4.1.22 \u2264 *","last_modified":"2026-05-11T12:46:03.691Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3115/","primary_source":"","published":"2026-05-11T08:45:33.754Z"},{"affected":"WSO2 Identity Server: 7.1.0 < 7.1.0.28","affected_versions_present":true,"cve_id":"CVE-2025-10503","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-10503","fixed":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4577/#solution","last_modified":"2026-04-29T12:28:52.278Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4577/","primary_source":"","published":"2026-04-29T08:08:37.335Z"},{"affected":"WSO2 Identity Server: < 5.2.0, 5.2.0 < 5.2.0.35","affected_versions_present":true,"cve_id":"CVE-2025-12624","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-12624","fixed":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4684/#solution","last_modified":"2026-04-16T12:30:14.886Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4684/","primary_source":"","published":"2026-04-16T10:25:19.789Z"},{"affected":"< 6.0.0; 6.0.0 < 6.0.0.247; 6.1.0 < 6.1.0.246; 7.0.0 < 7.0.0.122; 7.1.0 < 7.1.0.29; < 4.2.0; 4.2.0 < 4.2.0.150; 4.3.0 < 4.3.0.63","affected_versions_present":true,"cve_id":"CVE-2025-5770","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-5770","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-05T20:13:05.330Z","patch_url":"","primary_source":"","published":"2025-11-05T19:02:48.434Z"},{"affected":"< 5.10.0; 5.10.0 < 5.10.0.360; 5.11.0 < 5.11.0.399; 6.0.0 < 6.0.0.235; 6.1.0 < 6.1.0.230; 7.0.0 < 7.0.0.101; 7.1.0 < 7.1.0.32; < 6.6.0","affected_versions_present":true,"cve_id":"CVE-2025-3125","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-3125","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-20T04:14:55.775Z","patch_url":"","primary_source":"","published":"2025-11-05T14:49:44.597Z"},{"affected":"< 5.10.0; 5.10.0 < 5.10.0.361; 5.11.0 < 5.11.0.414; 6.0.0 < 6.0.0.245; 6.1.0 < 6.1.0.244; 7.0.0 < 7.0.0.119; 7.1.0 < 7.1.0.25; < 6.6.0","affected_versions_present":true,"cve_id":"CVE-2025-5605","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-5605","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-24T11:44:58.987Z","patch_url":"","primary_source":"","published":"2025-10-24T10:09:59.591Z"},{"affected":"< 5.10.0; 5.10.0 < 5.10.0.359; 5.11.0 < 5.11.0.415; 6.0.0 < 6.0.0.246; 6.1.0 < 6.1.0.245; 7.0.0 < 7.0.0.120; 7.1.0 < 7.1.0.27; < 6.6.0","affected_versions_present":true,"cve_id":"CVE-2025-5350","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-5350","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-24T12:16:49.892Z","patch_url":"","primary_source":"","published":"2025-10-24T10:08:07.719Z"},{"affected":"< 5.10.0; 5.10.0 < 5.10.0.346; 5.11.0 < 5.11.0.395; 6.0.0 < 6.0.0.231; 6.1.0 < 6.1.0.223; 2.0.0 < 2.0.0.390; 5.10.0 < 5.10.0.339","affected_versions_present":true,"cve_id":"CVE-2025-1396","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-1396","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-30T15:43:31.106Z","patch_url":"","primary_source":"","published":"2025-09-26T07:52:52.297Z"},{"affected":"7.0.0 < 7.0.0.87","affected_versions_present":true,"cve_id":"CVE-2025-0209","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-0209","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-23T18:37:43.867Z","patch_url":"","primary_source":"","published":"2025-09-23T17:13:10.597Z"},{"affected":"< 5.10.0; 5.10.0 < 5.10.0.278; 5.11.0 < 5.11.0.347; 6.0.0 < 6.0.0.185; 6.1.0 < 6.1.0.145; 7.0.0 < 7.0.0.30; < 3.1.0; 3.1.0 < 3.1.0.262","affected_versions_present":true,"cve_id":"CVE-2024-1440","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-1440","fixed":"7.0.111 \u2264 *","last_modified":"2025-06-02T17:07:01.605Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171/","primary_source":"","published":"2025-06-02T16:51:16.948Z"},{"affected":"7.0.0 < 7.0.0.65; 7.0.26 < 7.0.26.24; 7.0.78 < 7.0.78.44","affected_versions_present":true,"cve_id":"CVE-2024-7487","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-7487","fixed":"7.0.51 \u2264 *; 7.1.30 \u2264 *","last_modified":"2025-05-22T19:23:58.211Z","patch_url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3348/","primary_source":"","published":"2025-05-22T19:03:13.414Z"},{"affected":"7.0.0 < 7.0.0.64","affected_versions_present":true,"cve_id":"CVE-2024-7103","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-7103","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-22T18:48:11.459Z","patch_url":"","primary_source":"","published":"2025-05-22T18:41:12.235Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"WSO2"}}
