org.apache.wicket:wicket-core
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.wicket:wicket-corepage 1 of 1
- CVE-2014-0043MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.14.02017-10-03
vulnerable: 6.0.0 ... 6.9.1 (19 versions)
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security v…
- CVE-2014-3526HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.0-M32017-10-30
vulnerable: 7.0.0-M1, 7.0.0-M2
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
- CVE-2014-7808HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.0-M52017-09-15
vulnerable: 7.0.0-M1, 7.0.0-M2, 7.0.0-M3, 7.0.0-M4
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption prov…
- CVE-2016-6806HIGHCVSS 8.8EG 8.8✓ Fixed in 8.0.0-M22017-10-03
vulnerable: 8.0.0-M1
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP…
- CVE-2020-11976HIGHCVSS 7.5EG 7.5✓ Fixed in 9.0.02020-08-11
vulnerable: 9.0.0-M5
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Ap…
- CVE-2021-23937HIGHCVSS 7.5EG 7.5✓ Fixed in 7.18.02021-05-25
vulnerable: 1.5-RC1 ... 7.9.0 (85 versions)
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup ca…
- CVE-2026-43975MEDIUMCVSS 6.5EG 6.5✓ Fixed in 10.9.02026-05-06
vulnerable: 10.0.0 ... 10.8.0 (11 versions)
FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended …
Check whether org.apache.wicket:wicket-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.wicket:wicket-core CVEs against the assets you own.
Start Free Scan →