CVE-2020-14445: WSO2 Identity Server

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Basic Policy Editor user Interface.

Affected products

  • WSO2 Identity Server: up to and including 5.9.0
  • WSO2 Identity Server As Key Manager: up to and including 5.9.0

Published 2020-06-18. Last modified 2026-06-17.