Skip to content
CVE-2019-20435: Reflected XSS in WSO2 API Manager 2.6.0

CVE-2019-20435: Reflected XSS in WSO2 API Manager 2.6.0

Securin June 8, 2026

A vulnerability was discovered on WSO2 products inline API documentation editor page of the API Publisher. A reflected cross-site script (XSS) vulnerability allows an attacker to perform in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful request parameter for ‘docName.’

Reproduced in a sandboxed environment. Requires only LAN or WiFi adjacency.

The POST request docName variable is vulnerable to reflected Cross-Site Scripting (XSS) in the URL,

Post-exploitation outcomes mapped to CVSS impact metrics.

A runbook, not a checklist. Sequence matters — assume compromise before you act.

Download the relevant patch based on the product version.

Reconstructed from vendor advisories, CISA bulletins, and Securin research records.

Timeline recorded · Disclosure coordinated by Securin

Primary sources — NVD, CISA KEV, and machine-readable IoC feed.

Extracted Entities

Companies (1)

Platforms (1)

Vulnerabilities (2)