Apache Wicket 中网页生成时输入未正确净化(Improper neutralization of input) 标签由 提供,默认注册在所有 中。该解析器将查找到的标签文本原样写入标记(markup),且完全不读取任何转义设置,因此标签中的内容会被当作标记进行渲染。 当标签文本来自所关联组件的标签模型(通过 设置)时,该文本会未经转义地写入标记。如果表单组件的标签中包含攻击者可以影响的数据,则应用程序受影响。Wicket 无法确定模型值的来源,因此该数据是来自 HTTP 请求还是来自存储,属于应用程序自
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Wicket | 8.0.0 ~ 8.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58301 | 5.9 MEDIUM | Apache Shiro: Server-side POST request may be steered to an alternate host |
| CVE-2026-76984 | 5.1 MEDIUM | Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute |
| CVE-2026-76982 | 5.1 MEDIUM | Apache Wicket: XSS in Button via its model object |
| CVE-2026-75802 | 5.1 MEDIUM | Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and default |
| CVE-2026-71378 | Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationReq | |
| CVE-2026-71257 | Apache Wicket: Configured file upload limits are not enforced when the multipart request h | |
| CVE-2026-70449 | Apache Wicket: Path traversal in resource style/variation/locale |
No comments yet