CVE-2020-14444: WSO2 Identity Server
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy Administration user interface.
Affected products
- WSO2 Identity Server: up to and including 5.9.0
- WSO2 Identity Server As Key Manager: up to and including 5.9.0
Published 2020-06-18. Last modified 2026-06-17.