这段描述涉及 Apache Wicket 框架中网页生成过程中的输入未正确中和(即潜在的安全漏洞,通常指未对来自用户或外部数据的 HTML/文本进行适当的转义/转义处理)。 Apache Wicket 中网页生成时的输入中和不当 是 的基类。该类在生成下拉选择框( 元素)时,会将“默认选项”(即未选择任何选项时显示的条目)的内容原样写入标记(markup)中,而同一选择框中的其他选项内容则会根据 设置进行转义处理。这些默认选项的内容来源于 或 ,这两个方法均为 ,因此它们返回的值不一定是从资源束(resource
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Wicket | 8.0.0 ~ 8.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58301 | 5.9 MEDIUM | Apache Shiro: Server-side POST request may be steered to an alternate host |
| CVE-2026-76985 | 5.1 MEDIUM | Apache Wicket: XSS in Palette via getAdditionalAttributes |
| CVE-2026-76983 | 5.1 MEDIUM | Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel |
| CVE-2026-76984 | 5.1 MEDIUM | Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute |
| CVE-2026-76982 | 5.1 MEDIUM | Apache Wicket: XSS in Button via its model object |
| CVE-2026-75802 | 5.1 MEDIUM | Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and default |
| CVE-2026-71378 | Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationReq | |
| CVE-2026-71257 | Apache Wicket: Configured file upload limits are not enforced when the multipart request h | |
| CVE-2026-70449 | Apache Wicket: Path traversal in resource style/variation/locale |
No comments yet