CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-8591: api control plane from 4.5.0 (inclusive), before 4.5.0.44 (exclusive), from 4.6.0 (inclusive), before 4.6.0.8…

CVE-2025-8591. CVSS 3.1 base score 6.1 (MEDIUM, Source advisory). EPSS 0.00253 (percentile 0.15265), scored 2026-10-05.

Affected technology

api control plane · from 4.5.0 (inclusive), before 4.5.0.44 (exclusive)
wso2

api control plane · from 4.6.0 (inclusive), before 4.6.0.8 (exclusive)
wso2

api manager · from 3.1.0 (inclusive), before 3.1.0.355 (exclusive)
wso2

api manager · from 3.2.0 (inclusive), before 3.2.0.459 (exclusive)
wso2

api manager · from 3.2.1 (inclusive), before 3.2.1.78 (exclusive)
wso2

api manager · from 4.0.0 (inclusive), before 4.0.0.380 (exclusive)
wso2

api manager · from 4.1.0 (inclusive), before 4.1.0.243 (exclusive)
wso2

api manager · from 4.2.0 (inclusive), before 4.2.0.183 (exclusive)
wso2

api manager · from 4.3.0 (inclusive), before 4.3.0.94 (exclusive)
wso2

api manager · from 4.4.0 (inclusive), before 4.4.0.58 (exclusive)
wso2

api manager · from 4.5.0 (inclusive), before 4.5.0.43 (exclusive)
wso2

api manager · from 4.6.0 (inclusive), before 4.6.0.7 (exclusive)
wso2

identity server · from 5.10.0 (inclusive), before 5.10.0.384 (exclusive)
wso2

identity server · from 6.0.0 (inclusive), before 6.0.0.255 (exclusive)
wso2

identity server · from 7.0.0 (inclusive), before 7.0.0.131 (exclusive)
wso2

identity server · from 7.1.0 (inclusive), before 7.1.0.51 (exclusive)
wso2

identity server as key manager · from 5.10.0 (inclusive), before 5.10.0.375 (exclusive)
wso2

open banking am · from 2.0.0 (inclusive), before 2.0.0.404 (exclusive)
wso2

open banking iam · from 2.0.0 (inclusive), before 2.0.0.424 (exclusive)
wso2

traffic manager · from 4.5.0 (inclusive), before 4.5.0.42 (exclusive)
wso2

traffic manager · from 4.6.0 (inclusive), before 4.6.0.7 (exclusive)
wso2

universal gateway · from 4.5.0 (inclusive), before 4.5.0.42 (exclusive)
wso2

universal gateway · from 4.6.0 (inclusive), before 4.6.0.7 (exclusive)
wso2

WSO2 Identity Server · 5.10.0 to before 5.10.0.381, 5.10.0 to before 5.10.0.384, 6.0.0 to before 6.0.0.255, 7.0.0 to before 7.0.0.131, 7.1.0 to before 7.1.0.21, 7.1.0 to before 7.1.0.51
WSO2

WSO2 API Manager · 3.1.0 to before 3.1.0.355, 3.2.0 to before 3.2.0.459, 3.2.1 to before 3.2.1.78, 4.0.0 to before 4.0.0.380, 4.1.0 to before 4.1.0.243, 4.2.0 to before 4.2.0.183, 4.3.0 to before 4.3.0.94, 4.4.0 to before 4.4.0.58, 4.5.0 to before 4.5.0.43, 4.6.0 to before 4.6.0.7
WSO2

WSO2 API Control Plane · 4.5.0 to before 4.5.0.44, 4.6.0 to before 4.6.0.8
WSO2

WSO2 Traffic Manager · 4.5.0 to before 4.5.0.42, 4.6.0 to before 4.6.0.7
WSO2

WSO2 Universal Gateway · 4.5.0 to before 4.5.0.42, 4.6.0 to before 4.6.0.7
WSO2

WSO2 Open Banking AM · 2.0.0 to before 2.0.0.404
WSO2

WSO2 Identity Server as Key Manager · 5.10.0 to before 5.10.0.375
WSO2

WSO2 Open Banking IAM · 2.0.0 to before 2.0.0.424
WSO2

Description’s affected range: before reflecting it back to the user's browser

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

An attacker can inject malicious script content into pages served by the application. Source advisory’s CVSS 3.1 assessment (base score 6.1/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-79
CCR priority
24.5 /100 (P4)
CVSS 3.1
6.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N · Source advisory
EPSS
0.00253 · percentile 0.15265 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-8591.html