Filtered by vendor Wso2 Subscriptions
Filtered by product Org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-13590 1 Wso2 9 Api Control Plane, Api Manager, Org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl and 6 more 2026-02-20 9.1 Critical
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.