VendorsApachewicketall versions
Vulnerabilities

Apache Software Foundation Wicket

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2024-36522
Apache Wicket: Remote code execution via XSLT injection
Published 2024-07-12 · Analyzed
9.8EPSS 0.021
CVE-2016-6793
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.
Published 2017-07-14 · Modified
9.1EPSS 0.085
CVE-2026-40010
Apache Wicket: possible session fixation using AuthenticatedWebSession
Published 2026-05-06 · Modified
9.1EPSS 0.004
CVE-2016-6806
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
Published 2017-10-02 · Modified
8.8EPSS 0.008
CVE-2021-23937
DNS proxy and possible amplification attack
Published 2021-05-25 · Modified
7.5EPSS 0.043
CVE-2020-11976
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
Published 2020-08-11 · Modified
7.5EPSS 0.038
CVE-2014-3526
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
Published 2017-10-30 · Modified
7.5EPSS 0.023
CVE-2014-7808
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.
Published 2017-09-15 · Modified
7.5EPSS 0.011
CVE-2026-71257
Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed
Published 2026-08-31 · Modified
7.5EPSS 0.008
CVE-2026-43646
Apache Wicket: crafted URLs can bypass PackageResourceGuard
Published 2026-05-06 · Analyzed
7.5EPSS 0.004
CVE-2024-53299
Apache Wicket: An attacker can intentionally trigger a memory leak
Published 2025-01-23 · Analyzed
6.5EPSS 0.015
CVE-2026-43975
Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager
Published 2026-05-06 · Analyzed
6.5EPSS 0.007
CVE-2024-27439
Apache Wicket: Possible bypass of CSRF protection
Published 2024-03-19 · Analyzed
6.5EPSS 0.007
CVE-2026-66391
Apache Wicket: leaked and missing CSP headers
Published 2026-07-27 · Analyzed
6.5EPSS 0.004
CVE-2015-5347
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to inject arbitrary web script or HTML via a ModalWindow title.
Published 2016-04-12 · Modified
6.1EPSS 0.082
CVE-2015-7520
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a crafted "value" attribute in a <input> element.
Published 2016-04-12 · Modified
6.1EPSS 0.052
CVE-2012-5636
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to <script> tags in a rendered response.
Published 2017-10-30 · Modified
6.1EPSS 0.035
CVE-2026-76986
Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue
Published 2026-08-31 · Analyzed
6.1EPSS 0.006
CVE-2026-66390
Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
Published 2026-07-27 · Analyzed
6.1EPSS 0.004
CVE-2026-42509
Apache Wicket: crafted strings can break out of the JavaScript sequence
Published 2026-05-06 · Modified
6.1EPSS 0.004
CVE-2026-75802
Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-76982
Apache Wicket: XSS in Button via its model object
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-76983
Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-76984
Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-76985
Apache Wicket: XSS in Palette via getAdditionalAttributes
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2014-0043
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.
Published 2017-10-02 · Modified
5.3EPSS 0.030
CVE-2026-70449
Apache Wicket: Path traversal in resource style/variation/locale
Published 2026-08-31 · Analyzed
5.3EPSS 0.009
CVE-2012-1089
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
Published 2012-03-23 · Modified
5.0EPSS 0.054
CVE-2013-2055
Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the information that is outside of wicket:panel markup.
Published 2014-02-10 · Modified
5.0EPSS 0.032
CVE-2026-71378
Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener
Published 2026-08-31 · Analyzed
4.6EPSS 0.002
CVE-2012-3373
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
Published 2012-09-19 · Modified
4.3EPSS 0.033
CVE-2012-0047
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
Published 2012-03-23 · Modified
4.3EPSS 0.030
CVE-2011-2712
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Published 2011-08-29 · Modified
2.6EPSS 0.033