CVE-2016-6793
- EPSS 4.85%
- Published 17.07.2017 13:18:06
- Last modified 20.04.2025 01:37:25
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java...
CVE-2015-7520
- EPSS 1.4%
- Published 12.04.2016 17:59:01
- Last modified 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HT...
CVE-2015-5347
- EPSS 1.71%
- Published 12.04.2016 17:59:00
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attac...
- EPSS 1.63%
- Published 10.02.2014 23:55:04
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and rea...
CVE-2012-3373
- EPSS 1.8%
- Published 19.09.2012 19:55:05
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.
- EPSS 2.3%
- Published 23.03.2012 18:55:01
- Last modified 11.04.2025 00:51:21
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
CVE-2012-0047
- EPSS 1.21%
- Published 23.03.2012 18:55:01
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
CVE-2011-2712
- EPSS 5.37%
- Published 29.08.2011 15:55:01
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.