CVE-2026-43975
Published May 6, 2026FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthentica…
- evidence mentions
- 3
- Buzz score
- 25.4