Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-4103 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API documents are viewed. Successful exploitation may result in the execution of malicious scripts within the user's browser context when viewing API documentation. Users with permissions to access the API documentation through these portals may be impacted, potentially allowing attackers to perform actions on behalf of the user, depending on their session privileges.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')WSO2 LLC

Affected Products

ProductVersions
WSO2 API Control Plane
4.6.0 (semver)
4.5.0 (semver)

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: 19moderate effort
  • Upgrade: 55moderate effort
  • Workaround:moderate effort

    Migrate to the latest unaffected version of WSO2 API Control Plane.

WSO2 API Manager
4.6.0 (semver)
4.5.0 (semver)
4.4.0 (semver)
4.3.0 (semver)
4.2.0 (semver)

CPE

  • cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 18moderate effort
  • Upgrade: 54moderate effort
  • Upgrade: 69moderate effort
  • Upgrade: 105moderate effort
  • Upgrade: 194moderate effort
  • Upgrade: 254moderate effort
  • Upgrade: 89moderate effort
  • Upgrade: 470moderate effort
  • Workaround:moderate effort

    Migrate to the latest unaffected version of WSO2 API Manager.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-4103
NVD Published Date:
Sep 14, 2026
NVD Last Modified:
Sep 18, 2026
Source:
WSO2 LLC