CVE-2020-24590: WSO2 API Manager
Critical severity, CVSS 9.1. EPSS: 1.3% chance of exploitation in the next 30 days.
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Affected products
Published 2020-08-21. Last modified 2026-06-17.