boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-12107

WSO2 Identity Server — Server-Side Template Injection via Velocity Template Engine in Multiple WSO2 Products Allows Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0065   49.3     —
AFFECTED
  Product          Versions  Fixed
  Identity Server  5.11.0 –  —
TIMELINE
  Oct 23  Reserved by WSO2
  Feb 19  Published (CNA: WSO2)
  Sep 3   RESCORED — CVE-2025-12107 (WSO2 Identity Server). CVSS 8.4 → 7.2 (NVD).
CWE-77, CWE-94 · CNA: WSO2 · CVSS v3.1 · 1 reference · NVD status: Modified

Description

The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax. Successful exploitation enables an attacker with administrative privileges to execute arbitrary template code on the server. This can lead to significant security consequences, including remote code execution, manipulation of data, and unauthorized access to sensitive information.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
October 23, 2025ReservedReserved by WSO2
February 19, 2026PublishedPublished (CNA: WSO2)
September 3, 2026RESCOREDRESCORED — CVE-2025-12107 (WSO2 Identity Server). CVSS 8.4 → 7.2 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
WSO2Identity Server—5.11.0—

Weaknesses

CWE-77 · CWE-94

References (1)

Related

Authoritative record: CVE-2025-12107 at cve.org

Vendors: wso2

Weaknesses: CWE-77 · CWE-94

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-12107 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.