Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
6.4
CVE-2026-4103PATCHED
wso2 · wso2 api control plane

Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution

Description

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API documents are viewed. Successful exploitation may result in the execution of malicious scripts within the user's browser context when viewing API documentation. Users with permissions to access the API documentation through these portals may be impacted, potentially allowing attackers to perform actions on behalf of the user, depending on their session privileges.

Affected Products

VendorProductVersions
wso2wso2 api control plane4.5.0, 4.6.0, 3.2.0, 3.2.1, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.5.0, 4.6.0

References

  • https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-4844/(vendor-advisory)

Related News (1 articles)

Tier C
VulDB13d ago
CVE-2026-4103 | WSO2 API Control Plane/API Manager HTML Sanitization HTML injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.16.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.5.0.554.6.0.193.2.0.4703.2.1.894.1.0.2544.2.0.1944.3.0.1054.4.0.694.5.0.544.6.0.18
CWECWE-79
PublishedSep 14, 2026
Trending Score4
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Trending: 54
MEDIUMCVE-2025-5802
Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery
Trending: 7
HIGHCVE-2026-19515
OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution
Trending: 7
LOWCVE-2025-13166
Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery
Trending: 4
MEDIUMCVE-2026-3096
Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 14, 2026
Discovered by ZDM
Sep 14, 2026
Patch Available
Sep 14, 2026