apache / wicket
11 known vulnerabilities in apache wicket.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-71257 | Medium | 0.8% | 7.5 | Apache Wicket enforces the upload limits configured on a form or upload field wh… | |
| CVE-2026-70449 | Low | 0.9% | 5.3 | Improper validation of resource URL attributes in Apache Wicket allows an unauth… | |
| CVE-2026-76986 | Low | 0.6% | 6.1 | Improper neutralization of input during web page generation in Apache Wicket. o… | |
| CVE-2026-75802 | Low | 0.5% | 5.4 | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null I… | |
| CVE-2026-76982 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation in Apache Wicket. o… | |
| CVE-2026-76983 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation in Apache Wicket. T… | |
| CVE-2026-76984 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation in Apache Wicket. o… | |
| CVE-2026-76985 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation in Apache Wicket. o… | |
| CVE-2026-66391 | Low | 0.4% | 6.5 | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability … | |
| CVE-2026-66390 | Low | 0.4% | 6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti… | |
| CVE-2026-71378 | Low | 0.2% | 4.6 | ResourceIsolationRequestCycleListener protects a Wicket application against cros… |