Apache

Wicket

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 31.08.2026 13:25:10
  • Zuletzt bearbeitet 01.09.2026 18:07:19

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is ...

  • EPSS 0.5%
  • Veröffentlicht 31.08.2026 13:22:18
  • Zuletzt bearbeitet 01.09.2026 18:07:38

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of e...

  • EPSS 0.5%
  • Veröffentlicht 31.08.2026 11:56:38
  • Zuletzt bearbeitet 01.09.2026 18:07:58

Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every WebApplication. The resolver writes...

  • EPSS 0.5%
  • Veröffentlicht 31.08.2026 11:56:15
  • Zuletzt bearbeitet 01.09.2026 18:07:45

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags. It escaped the attribute names it wrote, but ran the attribute values through a r...

  • EPSS 0.5%
  • Veröffentlicht 31.08.2026 11:52:26
  • Zuletzt bearbeitet 01.09.2026 18:08:08

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attribute it writes is not encoded twice — ComponentTa...

  • EPSS 0.5%
  • Veröffentlicht 31.08.2026 11:52:17
  • Zuletzt bearbeitet 01.09.2026 18:08:20

AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML escaping Wicket performs by default for component m...

  • EPSS 0.25%
  • Veröffentlicht 31.08.2026 11:46:27
  • Zuletzt bearbeitet 01.09.2026 18:08:38

ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a resource isolation policy judges to come from another origin. Its default policy, FetchMetadataResourceIsolationPolicy...

  • EPSS 0.78%
  • Veröffentlicht 31.08.2026 11:45:49
  • Zuletzt bearbeitet 01.09.2026 19:17:26

Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items an...

  • EPSS 0.91%
  • Veröffentlicht 31.08.2026 11:44:14
  • Zuletzt bearbeitet 01.09.2026 18:09:23

Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web application, including files under WEB-INF that the servlet container would not otherwise serve. The locale, style a...

  • EPSS 0.4%
  • Veröffentlicht 27.07.2026 16:45:17
  • Zuletzt bearbeitet 05.08.2026 18:41:31

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fi...