Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Wicket — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in Apache Wicket, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common weakness types associated with the Apache Wicket web application framework. It collects data on various security flaws, including input validation errors, cross-site scripting, and improper access control, covering reported incidents from its initial public releases through recent years. Visitors can track vendor advisories issued by the Apache Software Foundation to stay informed about patch availability and security updates. The resource allows users to understand the nature and impact of specific weakness classes within this particular technology stack. Additionally, it provides a historical view of vulnerabilities affecting Apache Wicket, enabling developers and security analysts to identify patterns in flaw discovery and remediation. By centralizing this information, the page supports informed decision-making regarding software maintenance and risk mitigation strategies. It serves as a reference point for assessing the security posture of applications built with Apache Wicket, highlighting critical areas that require attention or code review. The content is organized to facilitate quick lookup of known issues while providing context on their severity and resolution status. This approach helps teams prioritize security efforts based on actual threat data rather than speculative risks. Users can compare current implementations against historical vulnerabilities to ensure their applications are protected against previously exploited attack vectors.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-76986 Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue CWE-79 - - 2026-08-31
CVE-2026-76985 Apache Wicket: XSS in Palette via getAdditionalAttributes CWE-79 5.1 Medium 2026-08-31
CVE-2026-76983 Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel CWE-79 5.1 Medium 2026-08-31
CVE-2026-76984 Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute CWE-79 5.1 Medium 2026-08-31
CVE-2026-76982 Apache Wicket: XSS in Button via its model object CWE-79 5.1 Medium 2026-08-31
CVE-2026-75802 Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel CWE-79 5.1 Medium 2026-08-31
CVE-2026-71378 Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener CWE-352 - - 2026-08-31
CVE-2026-71257 Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed CWE-770 - - 2026-08-31
CVE-2026-70449 Apache Wicket: Path traversal in resource style/variation/locale CWE-22 - - 2026-08-31
CVE-2026-66391 Apache Wicket: leaked and missing CSP headers CWE-330 - - 2026-07-27
CVE-2026-66390 Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence CWE-79 - - 2026-07-27
CVE-2026-40010 Apache Wicket: possible session fixation using AuthenticatedWebSession 9.8AI Critical AI 2026-05-06
CVE-2026-42509 Apache Wicket: crafted strings can break out of the JavaScript sequence CWE-79 6.1AI Medium AI 2026-05-06
CVE-2026-43646 Apache Wicket: crafted URLs can bypass PackageResourceGuard CWE-200 7.5AI High AI 2026-05-06
CVE-2026-43975 Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager CWE-22 9.1AI Critical AI 2026-05-06
CVE-2024-53299 Apache Wicket: An attacker can intentionally trigger a memory leak CWE-400 7.5 - 2025-01-23
CVE-2024-36522 Apache Wicket: Remote code execution via XSLT injection CWE-74 9.8AI Critical AI 2024-07-12
CVE-2024-27439 Apache Wicket: Possible bypass of CSRF protection CWE-352 8.8 - 2024-03-19
CVE-2021-23937 DNS proxy and possible amplification attack 7.5 - 2021-05-25
CVE-2020-11976 Apache Wicket 信息泄露漏洞 6.5 - 2020-08-11
CVE-2014-0043 Apache Wicket 信息泄露漏洞 5.3 - 2017-10-02
CVE-2016-6806 Apache Wicket 跨站请求伪造漏洞 8.8 - 2017-10-02

All 22 known CVE vulnerabilities affecting Apache Wicket with full Chinese analysis, references, and POCs where available.