Vulnerability Database

309,540

Total vulnerabilities in the database

CVE-2025-2905

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products.

A successful XXE attack could allow a remote, unauthenticated attacker to:

  • Read sensitive files from the server’s filesystem.
  • Perform denial-of-service (DoS) attacks, which can render the affected service unavailable.

CVSS v3:

  • Severity: Unknown
  • Score:
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H