Apache Wicket

9 known vulnerabilities in Apache Wicket, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-76986 CVSS 6.1 medium Improper neutralization of input during web page generation in Apache Wicket…
  • CVE-2026-76985 CVSS 5.1 medium Improper neutralization of input during web page generation in Apache Wicket…
  • CVE-2026-76984 CVSS 5.1 medium Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates…
  • CVE-2026-76983 CVSS 5.1 medium Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by…
  • CVE-2026-76982 CVSS 5.1 medium Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the…
  • CVE-2026-75802 CVSS 5.1 medium AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from…
  • CVE-2026-71378 CVSS 4.6 medium ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests that a…
  • CVE-2026-71257 CVSS 7.5 high Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons…
  • CVE-2026-70449 CVSS 5.3 medium Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from the web…