Apache Wicket
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 21
Severity across 21 analyzed records
en
Severity across 21 analyzed records
Verify to analyze this security profile
As of 09/14/2026, within CyStack's analyzed data, Apache Wicket has 11 security vulnerabilities published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache Wicket and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-76986Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityMedium |
CVE-2026-76985Apache Wicket: XSS in Palette via getAdditionalAttributes | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityMedium |
CVE-2026-76983Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityMedium |
CVE-2026-76984Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityMedium |
CVE-2026-76982Apache Wicket: XSS in Button via its model object | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityMedium |
CVE-2026-75802Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityMedium |
CVE-2026-71378Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityMedium |
CVE-2026-71257Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityHigh |
CVE-2026-70449Apache Wicket: Path traversal in resource style/variation/locale | Exploitation statusNot known exploited | FixYes | Published08/31/2026 | SeverityMedium |
CVE-2026-66391Apache Wicket: leaked and missing CSP headers | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityMedium |
CVE-2026-66390Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence | Exploitation statusNot known exploited | FixYes | Published07/27/2026 | SeverityMedium |
CVE-2026-40010Apache Wicket: possible session fixation using AuthenticatedWebSession | Exploitation statusNot known exploited | FixYes | Published05/06/2026 | SeverityCritical |
CVE-2026-42509Apache Wicket: crafted strings can break out of the JavaScript sequence | Exploitation statusNot known exploited | FixYes | Published05/06/2026 | SeverityMedium |
CVE-2026-43646Apache Wicket: crafted URLs can bypass PackageResourceGuard | Exploitation statusNot known exploited | FixYes | Published05/06/2026 | SeverityHigh |
CVE-2026-43975Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager | Exploitation statusNot known exploited | FixYes | Published05/06/2026 | SeverityMedium |
CVE-2024-53299Apache Wicket: An attacker can intentionally trigger a memory leak | Exploitation statusNot known exploited | FixYes | Published01/23/2025 | SeverityMedium |
CVE-2024-36522Apache Wicket: Remote code execution via XSLT injection | Exploitation statusNot known exploited | FixYes | Published07/12/2024 | SeverityCritical |
CVE-2024-27439Apache Wicket: Possible bypass of CSRF protection | Exploitation statusNot known exploited | FixYes | Published03/19/2024 | SeverityMedium |
CVE-2021-23937DNS proxy and possible amplification attack | Exploitation statusNot confirmed | FixYes | Published05/25/2021 | SeverityUnknown |
CVE-2016-6806 | Exploitation statusNot confirmed | FixNot confirmed | Published10/02/2017 | SeverityUnknown |
CVE-2014-0043 | Exploitation statusNot confirmed | FixNot confirmed | Published10/02/2017 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan