CVE-2019-20439: WSO2 API Manager

Medium severity, CVSS 4.8. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in defining a scope in the "manage the API" page of the API Publisher.

Affected products

  • WSO2 API Manager: version 2.6.0 only

Published 2020-01-28. Last modified 2026-06-17.