CVE-2018-8716: WSO2 Identity Server

Medium severity, CVSS 5.4. EPSS: 38.1% chance of exploitation in the next 30 days.

WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.

Affected products

  • WSO2 Identity Server: before 5.5.0 (fixed in 5.5.0)

Published 2018-04-25. Last modified 2026-06-17.