Apache Wicket 中对资源 URL 属性的校验不当,使得未经身份验证的远程攻击者能够读取 Web 应用程序中的文件,包括 Servlet 容器原本不会直接提供的 WEB-INF 目录下的文件。 从包资源 URL 中解码出来的 locale、style 和 variation 属性,在拼接到资源查找路径时,并未检查其中是否包含路径分隔符。IPackageResourceGuard(其拒绝 ".." 本是两项预期控制措施之一)仅在附加这些属性之前对资源名称进行检查,而 WebApplicationPath 仅
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Wicket | 8.0.0 ~ 8.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58301 | 5.9 MEDIUM | Apache Shiro: Server-side POST request may be steered to an alternate host |
| CVE-2026-76983 | 5.1 MEDIUM | Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel |
| CVE-2026-76984 | 5.1 MEDIUM | Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute |
| CVE-2026-76982 | 5.1 MEDIUM | Apache Wicket: XSS in Button via its model object |
| CVE-2026-75802 | 5.1 MEDIUM | Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and default |
| CVE-2026-71378 | Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationReq | |
| CVE-2026-71257 | Apache Wicket: Configured file upload limits are not enforced when the multipart request h |
No comments yet