CVE-2026-76986
- EPSS 0.56%
- Veröffentlicht 31.08.2026 13:25:10
- Zuletzt bearbeitet 01.09.2026 18:07:19
Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is ...
CVE-2026-76985
- EPSS 0.5%
- Veröffentlicht 31.08.2026 13:22:18
- Zuletzt bearbeitet 01.09.2026 18:07:38
Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of e...
CVE-2026-76983
- EPSS 0.5%
- Veröffentlicht 31.08.2026 11:56:38
- Zuletzt bearbeitet 01.09.2026 18:07:58
Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every WebApplication. The resolver writes...
CVE-2026-76984
- EPSS 0.5%
- Veröffentlicht 31.08.2026 11:56:15
- Zuletzt bearbeitet 01.09.2026 18:07:45
Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags. It escaped the attribute names it wrote, but ran the attribute values through a r...
CVE-2026-76982
- EPSS 0.5%
- Veröffentlicht 31.08.2026 11:52:26
- Zuletzt bearbeitet 01.09.2026 18:08:08
Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it writes is not encoded twice — ComponentTa...
CVE-2026-75802
- EPSS 0.5%
- Veröffentlicht 31.08.2026 11:52:17
- Zuletzt bearbeitet 01.09.2026 18:08:20
AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML escaping Wicket performs by default for component m...
CVE-2026-71378
- EPSS 0.25%
- Veröffentlicht 31.08.2026 11:46:27
- Zuletzt bearbeitet 01.09.2026 18:08:38
ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default policy, FetchMetadataResourceIsolationPolicy...
CVE-2026-71257
- EPSS 0.78%
- Veröffentlicht 31.08.2026 11:45:49
- Zuletzt bearbeitet 01.09.2026 19:17:26
Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items an...
CVE-2026-70449
- EPSS 0.91%
- Veröffentlicht 31.08.2026 11:44:14
- Zuletzt bearbeitet 01.09.2026 18:09:23
Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF that the servlet container would not otherwise serve. The locale, style a...
CVE-2026-66391
- EPSS 0.4%
- Veröffentlicht 27.07.2026 16:45:17
- Zuletzt bearbeitet 05.08.2026 18:41:31
Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fi...