Apache

Wicket

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 30.10.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.

  • EPSS 0.17%
  • Veröffentlicht 03.10.2017 01:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header int...

  • EPSS 1.51%
  • Veröffentlicht 03.10.2017 01:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerabilit...

  • EPSS 0.27%
  • Veröffentlicht 15.09.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.

  • EPSS 3.63%
  • Veröffentlicht 17.07.2017 13:18:06
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java...

  • EPSS 1.4%
  • Veröffentlicht 12.04.2016 17:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HT...

Exploit
  • EPSS 1.71%
  • Veröffentlicht 12.04.2016 17:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attac...

  • EPSS 1.63%
  • Veröffentlicht 10.02.2014 23:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and rea...

  • EPSS 1.8%
  • Veröffentlicht 19.09.2012 19:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.

  • EPSS 1.54%
  • Veröffentlicht 23.03.2012 18:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.