Exposure of Apache Wicket

Web frameworks
40
exposure score
1,870
sites use
0
exploited
2
critical
Vexday analysis

Apache Wicket apresenta um histórico de vulnerabilidades relativamente contido, com 11 CVEs catalogadas e taxa de exploração ativa abaixo da média geral do catálogo, sem registros no CISA KEV. Ainda assim, merecem atenção os dois registros de severidade crítica e, em especial, o volume de quatro novas vulnerabilidades surgidas nos últimos 90 dias, o que indica atividade recente de descoberta que deve ser monitorada. A falha mais prevalente segue o padrão CWE-200, relacionado à exposição indevida de informações, sugerindo que controles de acesso e gerenciamento de dados sensíveis no framework requerem revisão cuidadosa. A CVE mais perigosa atualmente ativa, CVE-2021-23937, registra EPSS de 0,0426, indicando probabilidade de exploração ainda moderada, mas não desprezível para ambientes expostos.

CVEs

22 results
CVE-2021-23937DNS proxy and possible amplification attackEPSS 4.3%CVE-2020-11976By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly senEPSS 3.8%CVE-2014-0043In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of partiEPSS 3.5%CVE-2024-36522CRITICALApache Wicket: Remote code execution via XSLT injectionEPSS 2.1%CVE-2024-53299MEDIUMApache Wicket: An attacker can intentionally trigger a memory leakEPSS 1.5%CVE-2026-70449MEDIUMApache Wicket: Path traversal in resource style/variation/localeEPSS 0.9%CVE-2016-6806Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin rEPSS 0.9%CVE-2026-71257HIGHApache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsedEPSS 0.8%CVE-2026-43975MEDIUMApache Wicket: Possible malicious path traversal in FolderUploadsFileManagerEPSS 0.7%CVE-2024-27439MEDIUMApache Wicket: Possible bypass of CSRF protectionEPSS 0.7%CVE-2026-76986MEDIUMApache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValueEPSS 0.6%CVE-2026-76985MEDIUMApache Wicket: XSS in Palette via getAdditionalAttributesEPSS 0.5%CVE-2026-75802MEDIUMApache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabelEPSS 0.5%CVE-2026-76982MEDIUMApache Wicket: XSS in Button via its model objectEPSS 0.5%CVE-2026-76983MEDIUMApache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabelEPSS 0.5%CVE-2026-76984MEDIUMApache Wicket: XSS in MetaDataHeaderItem via addTagAttributeEPSS 0.5%CVE-2026-66391MEDIUMApache Wicket: leaked and missing CSP headersEPSS 0.4%CVE-2026-43646HIGHApache Wicket: crafted URLs can bypass PackageResourceGuardEPSS 0.4%CVE-2026-40010CRITICALApache Wicket: possible session fixation using AuthenticatedWebSessionEPSS 0.4%CVE-2026-42509MEDIUMApache Wicket: crafted strings can break out of the JavaScript sequenceEPSS 0.4%