Apache / Wicket
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-76986 | Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue | MEDIUM | 6.1 | Aug 31, 2026 |
| CVE-2026-76985 | Apache Wicket: XSS in Palette via getAdditionalAttributes | MEDIUM | 5.1 | Aug 31, 2026 |
| CVE-2026-76983 | Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel | MEDIUM | 5.1 | Aug 31, 2026 |
| CVE-2026-76984 | Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute | MEDIUM | 5.1 | Aug 31, 2026 |
| CVE-2026-76982 | Apache Wicket: XSS in Button via its model object | MEDIUM | 5.1 | Aug 31, 2026 |
| CVE-2026-75802 | Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel | MEDIUM | 5.1 | Aug 31, 2026 |
| CVE-2026-71378 | Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener | MEDIUM | 4.6 | Aug 31, 2026 |
| CVE-2026-71257 | Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed | HIGH | 7.5 | Aug 31, 2026 |
| CVE-2026-70449 | Apache Wicket: Path traversal in resource style/variation/locale | MEDIUM | 5.3 | Aug 31, 2026 |
| CVE-2026-66391 | Apache Wicket: leaked and missing CSP headers | MEDIUM | 6.5 | Jul 27, 2026 |
| CVE-2026-66390 | Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence | MEDIUM | 6.1 | Jul 27, 2026 |
| CVE-2026-40010 | Apache Wicket: possible session fixation using AuthenticatedWebSession | CRITICAL | 9.1 | May 6, 2026 |
| CVE-2026-42509 | Apache Wicket: crafted strings can break out of the JavaScript sequence | MEDIUM | 6.1 | May 6, 2026 |
| CVE-2026-43646 | Apache Wicket: crafted URLs can bypass PackageResourceGuard | HIGH | 7.5 | May 6, 2026 |
| CVE-2026-43975 | Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager | MEDIUM | 6.5 | May 6, 2026 |
| CVE-2024-53299 | Apache Wicket: An attacker can intentionally trigger a memory leak | MEDIUM | 6.5 | Jan 23, 2025 |
| CVE-2024-36522 | Apache Wicket: Remote code execution via XSLT injection | CRITICAL | 9.8 | Jul 12, 2024 |
| CVE-2024-27439 | Apache Wicket: Possible bypass of CSRF protection | HIGH | 8.1 | Mar 19, 2024 |
| CVE-2021-23937 | DNS proxy and possible amplification attack | HIGH | 7.5 | May 25, 2021 |
| CVE-2020-11976 | By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information… | HIGH | 7.5 | Aug 11, 2020 |
| CVE-2012-5636 | Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject… | MEDIUM | 6.1 | Oct 30, 2017 |
| CVE-2014-3526 | Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving iden… | HIGH | 7.5 | Oct 30, 2017 |
| CVE-2016-6806 | Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitiga… | HIGH | 8.8 | Oct 2, 2017 |
| CVE-2014-0043 | In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in th… | MEDIUM | 5.3 | Oct 2, 2017 |
| CVE-2014-7808 | Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict… | HIGH | 7.5 | Sep 15, 2017 |
Showing 1 to 25 of 33 CVEs