在 Apache Wicket 中生成网页时,输入未得到适当中和(即输入校验/转义处理不当)。 具体而言, 负责渲染 Palette 中的两个选项列表。该组件会根据 的设置对每个选项的 ID 和显示值进行转义处理,但会将 返回的属性名和属性值原样写入 标签中,而未做转义或过滤。 当应用重写了 、 或 方法,并返回一个包含攻击者可控制的数据时,该应用将受到影响。由于这些方法默认返回 ,因此未重写它们的应用不受影响。 作为临时解决方案,可在重写方法中对返回值进行转义处理。 此问题影响以下 Apache Wicket 版
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Wicket | 8.0.0 ~ 8.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58301 | 5.9 MEDIUM | Apache Shiro: Server-side POST request may be steered to an alternate host |
| CVE-2026-76983 | 5.1 MEDIUM | Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel |
| CVE-2026-76984 | 5.1 MEDIUM | Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute |
| CVE-2026-76982 | 5.1 MEDIUM | Apache Wicket: XSS in Button via its model object |
| CVE-2026-75802 | 5.1 MEDIUM | Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and default |
| CVE-2026-76986 | Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue | |
| CVE-2026-71378 | Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationReq | |
| CVE-2026-71257 | Apache Wicket: Configured file upload limits are not enforced when the multipart request h | |
| CVE-2026-70449 | Apache Wicket: Path traversal in resource style/variation/locale |
No comments yet