Apache
Apache Wicket: vulnerabilidades y CVE
Apache Wicket tiene 33 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses15
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76986 | Media (6.1) | 0.57% | — | 31 ago 2026 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the… |
| CVE-2026-76985 | Media (5.1) | 0.51% | — | 31 ago 2026 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the… |
| CVE-2026-76984 | Media (5.1) | 0.51% | — | 31 ago 2026 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags. It escaped the attribute names it wrote, but ran… |
| CVE-2026-76983 | Media (5.1) | 0.51% | — | 31 ago 2026 | Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every… |
| CVE-2026-76982 | Media (5.1) | 0.51% | — | 31 ago 2026 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it writes is… |
| CVE-2026-75802 | Media (5.1) | 0.51% | — | 31 ago 2026 | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML escaping Wicket… |
| CVE-2026-71378 | Media (4.6) | 0.25% | — | 31 ago 2026 | ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default policy,… |
| CVE-2026-71257 | Alta (7.5) | 0.74% | — | 31 ago 2026 | Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons… |
| CVE-2026-70449 | Media (5.3) | 0.91% | — | 31 ago 2026 | Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF that the servlet container would not… |
| CVE-2026-66391 | Media (6.5) | 0.64% | — | 27 jul 2026 | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade… |
| CVE-2026-66390 | Media (6.1) | 0.57% | — | 27 jul 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are… |
| CVE-2026-43975 | Media (6.5) | 1.0% | — | 6 may 2026 | FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files… |
| CVE-2026-43646 | Alta (7.5) | 0.62% | — | 6 may 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0. Users are… |
| CVE-2026-42509 | Media (6.1) | 0.57% | — | 6 may 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users… |
| CVE-2026-40010 | Crítica (9.1) | 0.61% | — | 6 may 2026 | Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0,… |
| CVE-2024-53299 | Media (6.5) | 1.5% | — | 23 ene 2025 | The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which… |
| CVE-2024-36522 | Crítica (9.8) | 2.1% | — | 12 jul 2024 | The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. Users are recommended to upgrade to… |
| CVE-2024-27439 | Media (6.5) | 0.68% | — | 19 mar 2024 | An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0… |
| CVE-2021-23937 | Alta (7.5) | 4.3% | — | 25 may 2021 | A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly… |
| CVE-2020-11976 | Alta (7.5) | 3.8% | — | 11 ago 2020 | By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during… |
| CVE-2012-5636 | Media (6.1) | 3.5% | — | 30 oct 2017 | Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vectors related to… |
| CVE-2014-3526 | Alta (7.5) | 2.3% | — | 30 oct 2017 | Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions. |
| CVE-2016-6806 | Alta (8.8) | 0.82% | — | 3 oct 2017 | Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also… |
| CVE-2014-0043 | Media (5.3) | 3.0% | — | 3 oct 2017 | In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library… |
| CVE-2014-7808 | Alta (7.5) | 1.1% | — | 15 sept 2017 | Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the… |
| CVE-2016-6793 | Crítica (9.1) | 8.5% | — | 17 jul 2017 | The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of… |
| CVE-2015-7520 | Media (6.1) | 5.2% | — | 12 abr 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to… |
| CVE-2015-5347 | Media (6.1) | 8.2% | — | 12 abr 2016 | Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before… |
| CVE-2013-2055 | Media (5) | 3.2% | — | 10 feb 2014 | Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered… |
| CVE-2012-3373 | Media (4.3) | 3.3% | — | 19 sept 2012 | Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.