Skip to main content

Vendor/product archive

apache / wicket CVEs

Beta · best-effort

22 CVEs tagged to apache / wicket3 Critical, 6 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2026-43975

Published May 6, 2026

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthentica…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-43646

Published May 6, 2026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0,…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42509

Published May 6, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0,…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-40010

Published May 6, 2026

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Ap…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-53299

Published Jan 23, 2025

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36522

Published Jul 12, 2024

The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. U…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-27439

Published Mar 19, 2024

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23937

Published May 25, 2021

A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11976

Published Aug 11, 2020

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML templa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5636

Published Oct 30, 2017

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web scrip…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3526

Published Oct 30, 2017

Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6806

Published Oct 3, 2017

Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0043

Published Oct 3, 2017

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7808

Published Sep 15, 2017

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6793

Published Jul 17, 2017

The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and dele…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7520

Published Apr 12, 2016

Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x b…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5347

Published Apr 12, 2016

Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2055

Published Feb 10, 2014

Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3373

Published Sep 19, 2012

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors inv…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1089

Published Mar 23, 2012

Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathna…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0047

Published Mar 23, 2012

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2712

Published Aug 29, 2011

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web scri…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1