Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-12107
WSO2 Identity Server — Server-Side Template Injection via Velocity Template Engine in Multiple WSO2 Products Allows Remote Code Execution
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H H H 7.2 .0065 49.3 —
AFFECTED
Product Versions Fixed
Identity Server 5.11.0 – —
TIMELINE
Oct 23 Reserved by WSO2
Feb 19 Published (CNA: WSO2)
Sep 3 RESCORED — CVE-2025-12107 (WSO2 Identity Server). CVSS 8.4 → 7.2 (NVD).
Description
The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax.
Successful exploitation enables an attacker with administrative privileges to execute arbitrary template code on the server. This can lead to significant security consequences, including remote code execution, manipulation of data, and unauthorized access to sensitive information.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| October 23, 2025 | Reserved | Reserved by WSO2 |
| February 19, 2026 | Published | Published (CNA: WSO2) |
| September 3, 2026 | RESCORED | RESCORED — CVE-2025-12107 (WSO2 Identity Server). CVSS 8.4 → 7.2 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| WSO2 | Identity Server | — | 5.11.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-12107 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.