All 7 CVE vulnerabilities found in Apache Wicket, with AI-generated Chinese analysis, references, and POCs.
Vendor: Apache Software Foundation
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2024-53299 | Apache Wicket: An attacker can intentionally trigger a memory leak CWE-400 | 7.5 | - | 2025-01-23 |
| CVE-2024-36522 | Apache Wicket: Remote code execution via XSLT injection CWE-74 | 9.8AI | CriticalAI | 2024-07-12 |
| CVE-2024-27439 | Apache Wicket: Possible bypass of CSRF protection CWE-352 | 8.8 | - | 2024-03-19 |
| CVE-2021-23937 | DNS proxy and possible amplification attack | 7.5 | - | 2021-05-25 |
| CVE-2020-11976 | Apache Wicket 信息泄露漏洞 | 6.5 | - | 2020-08-11 |
| CVE-2014-0043 | Apache Wicket 信息泄露漏洞 | 5.3 | - | 2017-10-02 |
| CVE-2016-6806 | Apache Wicket 跨站请求伪造漏洞 | 8.8 | - | 2017-10-02 |
All 7 known CVE vulnerabilities affecting Apache Wicket with full Chinese analysis, references, and POCs where available.