Apache wicket
This hub aggregates every CVE we track for Apache wicket, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
21
CVEs tracked
2
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM15HIGH4CRITICAL2
Monthly trend
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
4
0
2
9
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache wicket.
- CVE-2026-76986Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue6.1
- CVE-2026-76985Apache Wicket: XSS in Palette via getAdditionalAttributes5.4
- CVE-2026-76983Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel5.4
- CVE-2026-76984Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute5.4
- CVE-2026-76982Apache Wicket: XSS in Button via its model object5.4
- CVE-2026-75802Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel5.4
- CVE-2026-71378Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener4.6
- CVE-2026-71257Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed7.5
- CVE-2026-70449Apache Wicket: Path traversal in resource style/variation/locale5.3
- CVE-2026-66391Apache Wicket: leaked and missing CSP headers6.5
- CVE-2026-66390Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence6.1
- CVE-2026-40010Apache Wicket: possible session fixation using AuthenticatedWebSession9.1
- CVE-2026-42509Apache Wicket: crafted strings can break out of the JavaScript sequence6.1
- CVE-2026-43646Apache Wicket: crafted URLs can bypass PackageResourceGuard7.5
- CVE-2026-43975Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager6.5
Product normalization is registry-driven with AI assist and human review. How it works