Vulnerabilities
Vulnerable Software
Apache:  >> Wicket  >> 9.17.0  Security Vulnerabilities
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.
CVSS Score
6.5
EPSS Score
0.003
Published
2025-01-23
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. Users are recommended to upgrade to versions 10.1.0, 9.18.0 or 8.16.0, which fix this issue.
CVSS Score
9.8
EPSS Score
0.031
Published
2024-07-12


Contact Us

Shodan ® - All rights reserved