VendorsApachewicketany version
Vulnerabilities

Apache Software Foundation Wicket any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2024-36522
Apache Wicket: Remote code execution via XSLT injection
Published 2024-07-12 · Analyzed
9.8EPSS 0.021
CVE-2016-6793
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.
Published 2017-07-14 · Modified
9.1EPSS 0.085
CVE-2026-40010
Apache Wicket: possible session fixation using AuthenticatedWebSession
Published 2026-05-06 · Modified
9.1EPSS 0.006
CVE-2021-23937
DNS proxy and possible amplification attack
Published 2021-05-25 · Modified
7.5EPSS 0.043
CVE-2020-11976
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
Published 2020-08-11 · Modified
7.5EPSS 0.038
CVE-2014-3526
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
Published 2017-10-30 · Modified
7.5EPSS 0.023
CVE-2014-7808
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.
Published 2017-09-15 · Modified
7.5EPSS 0.011
CVE-2026-71257
Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed
Published 2026-08-31 · Modified
7.5EPSS 0.007
CVE-2026-43646
Apache Wicket: crafted URLs can bypass PackageResourceGuard
Published 2026-05-06 · Analyzed
7.5EPSS 0.006
CVE-2024-53299
Apache Wicket: An attacker can intentionally trigger a memory leak
Published 2025-01-23 · Analyzed
6.5EPSS 0.015
CVE-2026-43975
Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager
Published 2026-05-06 · Analyzed
6.5EPSS 0.010
CVE-2024-27439
Apache Wicket: Possible bypass of CSRF protection
Published 2024-03-19 · Analyzed
6.5EPSS 0.007
CVE-2026-66391
Apache Wicket: leaked and missing CSP headers
Published 2026-07-27 · Analyzed
6.5EPSS 0.006
CVE-2015-5347
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to inject arbitrary web script or HTML via a ModalWindow title.
Published 2016-04-12 · Modified
6.1EPSS 0.082
CVE-2015-7520
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a crafted "value" attribute in a <input> element.
Published 2016-04-12 · Modified
6.1EPSS 0.052
CVE-2026-42509
Apache Wicket: crafted strings can break out of the JavaScript sequence
Published 2026-05-06 · Modified
6.1EPSS 0.006
CVE-2026-66390
Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
Published 2026-07-27 · Analyzed
6.1EPSS 0.006
CVE-2026-76986
Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue
Published 2026-08-31 · Analyzed
6.1EPSS 0.006
CVE-2026-75802
Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-76982
Apache Wicket: XSS in Button via its model object
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-76983
Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-76984
Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-76985
Apache Wicket: XSS in Palette via getAdditionalAttributes
Published 2026-08-31 · Analyzed
5.4EPSS 0.005
CVE-2026-70449
Apache Wicket: Path traversal in resource style/variation/locale
Published 2026-08-31 · Analyzed
5.3EPSS 0.009
CVE-2026-71378
Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener
Published 2026-08-31 · Analyzed
4.6EPSS 0.003