Known Vulnerabilities for Apache Wicket by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache Wicket" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-76986 json | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSin... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-76985 json | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-76984 json | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderIt... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-76983 json | Improper neutralization of input during web page generation in Apache Wicket.
The |
Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-76982 json | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clea... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-75802 json | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obta... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-71378 json | ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forgery by rejecting requests... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-71257 json | Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache C... | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-70449 json | Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to read files from ... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-66391 json | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache ... | Not Provided | 2026-07-27 | 2026-07-28 |