Get real-time updates on Telegram
CVE-2025-8591: api control plane from 4.5.0 (inclusive), before 4.5.0.44 (exclusive), from 4.6.0 (inclusive), before 4.6.0.8…
CVE-2025-8591. CVSS 3.1 base score 6.1 (MEDIUM, Source advisory). EPSS 0.00253 (percentile 0.15265), scored 2026-10-05.
Affected technology
api control plane · from 4.5.0 (inclusive), before 4.5.0.44 (exclusive)
wso2
api control plane · from 4.6.0 (inclusive), before 4.6.0.8 (exclusive)
wso2
api manager · from 3.1.0 (inclusive), before 3.1.0.355 (exclusive)
wso2
api manager · from 3.2.0 (inclusive), before 3.2.0.459 (exclusive)
wso2
api manager · from 3.2.1 (inclusive), before 3.2.1.78 (exclusive)
wso2
api manager · from 4.0.0 (inclusive), before 4.0.0.380 (exclusive)
wso2
api manager · from 4.1.0 (inclusive), before 4.1.0.243 (exclusive)
wso2
api manager · from 4.2.0 (inclusive), before 4.2.0.183 (exclusive)
wso2
api manager · from 4.3.0 (inclusive), before 4.3.0.94 (exclusive)
wso2
api manager · from 4.4.0 (inclusive), before 4.4.0.58 (exclusive)
wso2
api manager · from 4.5.0 (inclusive), before 4.5.0.43 (exclusive)
wso2
api manager · from 4.6.0 (inclusive), before 4.6.0.7 (exclusive)
wso2
identity server · from 5.10.0 (inclusive), before 5.10.0.384 (exclusive)
wso2
identity server · from 6.0.0 (inclusive), before 6.0.0.255 (exclusive)
wso2
identity server · from 7.0.0 (inclusive), before 7.0.0.131 (exclusive)
wso2
identity server · from 7.1.0 (inclusive), before 7.1.0.51 (exclusive)
wso2
identity server as key manager · from 5.10.0 (inclusive), before 5.10.0.375 (exclusive)
wso2
open banking am · from 2.0.0 (inclusive), before 2.0.0.404 (exclusive)
wso2
open banking iam · from 2.0.0 (inclusive), before 2.0.0.424 (exclusive)
wso2
traffic manager · from 4.5.0 (inclusive), before 4.5.0.42 (exclusive)
wso2
traffic manager · from 4.6.0 (inclusive), before 4.6.0.7 (exclusive)
wso2
universal gateway · from 4.5.0 (inclusive), before 4.5.0.42 (exclusive)
wso2
universal gateway · from 4.6.0 (inclusive), before 4.6.0.7 (exclusive)
wso2
WSO2 Identity Server · 5.10.0 to before 5.10.0.381, 5.10.0 to before 5.10.0.384, 6.0.0 to before 6.0.0.255, 7.0.0 to before 7.0.0.131, 7.1.0 to before 7.1.0.21, 7.1.0 to before 7.1.0.51
WSO2
WSO2 API Manager · 3.1.0 to before 3.1.0.355, 3.2.0 to before 3.2.0.459, 3.2.1 to before 3.2.1.78, 4.0.0 to before 4.0.0.380, 4.1.0 to before 4.1.0.243, 4.2.0 to before 4.2.0.183, 4.3.0 to before 4.3.0.94, 4.4.0 to before 4.4.0.58, 4.5.0 to before 4.5.0.43, 4.6.0 to before 4.6.0.7
WSO2
WSO2 API Control Plane · 4.5.0 to before 4.5.0.44, 4.6.0 to before 4.6.0.8
WSO2
WSO2 Traffic Manager · 4.5.0 to before 4.5.0.42, 4.6.0 to before 4.6.0.7
WSO2
WSO2 Universal Gateway · 4.5.0 to before 4.5.0.42, 4.6.0 to before 4.6.0.7
WSO2
WSO2 Open Banking AM · 2.0.0 to before 2.0.0.404
WSO2
WSO2 Identity Server as Key Manager · 5.10.0 to before 5.10.0.375
WSO2
WSO2 Open Banking IAM · 2.0.0 to before 2.0.0.424
WSO2
Description’s affected range: before reflecting it back to the user's browser
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
An attacker can inject malicious script content into pages served by the application. Source advisory’s CVSS 3.1 assessment (base score 6.1/10) rates confidentiality and integrity impact as low; availability impact as none.
- CWE
- CWE-79
- CCR priority
- 24.5 /100 (P4)
- CVSS 3.1
- 6.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N · Source advisory
- EPSS
- 0.00253 · percentile 0.15265 · 2026-10-05
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 02:34:12.333111+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-8591.html