VYPR

Wicket

by Apache

Source repositories

CVEs (33)

  • CVE-2026-76984MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates and header tags. It escaped the attribute names it wrote, but ran the attribute values through a replacement of " with \". A…

  • CVE-2026-76983MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every WebApplication. The resolver writes the label it finds into the…

  • CVE-2026-76982MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it writes is not encoded twice — ComponentTag already encodes attribute…

  • CVE-2026-75802MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.01

    AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML escaping Wicket performs by default for component model values. An attacker who…

  • CVE-2026-43975MedMay 6, 2026
    risk 0.35cvss 6.5epss 0.01

    FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended upload directory or read files from…

  • CVE-2014-0043MedOct 3, 2017
    risk 0.35cvss 5.3epss 0.04

    In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.

  • CVE-2026-70449MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.01

    Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF that the servlet container would not otherwise serve. The locale, style and variation attributes…

  • CVE-2026-71378MedAug 31, 2026
    risk 0.23cvss 4.6epss 0.00

    ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default policy, FetchMetadataResourceIsolationPolicy, was derived from a…

  • CVE-2013-2055Feb 10, 2014
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the information that is…

  • CVE-2012-3373Sep 19, 2012
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.

  • CVE-2012-1089Mar 23, 2012
    risk 0.00cvss —epss 0.05

    Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.

  • CVE-2012-0047Mar 23, 2012
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.

  • CVE-2011-2712Aug 29, 2011
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Page 2 of 2