Vendor
critical
advisory
CVE-2026-5430: Path Traversal and RCE in WSO2 Products
2 TTPs 1 CVEMultiple WSO2 products are vulnerable to a path traversal flaw that allows unauthenticated attackers to perform unrestricted file uploads, resulting in potential remote code execution.
API Control Plane +3
cve
path-traversal
rce
wso2
2t
1c
high
advisory
WSO2 Products Vulnerable to XML External Entity (XXE) Injection via CVE-2024-2374
2 rules 2 TTPsCVE-2024-2374 describes an XML External Entity (XXE) vulnerability in multiple WSO2 products, where improperly configured XML parsers allow attackers to inject malicious XML payloads to include external resources, leading to confidential file access, limited HTTP resource access, and denial-of-service attacks.
WSO2
xxe
cve-2024-2374
xml
vulnerability
attack
cloud
network
2r
2t