CVE-2019-20441: WSO2 API Manager

Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in WSO2 API Manager 2.6.0. A potential Stored Cross-Site Scripting (XSS) vulnerability has been identified in the 'implement phase' of the API Publisher.

Affected products

  • WSO2 API Manager: version 2.6.0 only

Published 2020-01-28. Last modified 2026-06-17.