CVE-2011-2712

Apache Wicket - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Scores

EPSS 0.0537
EPSS Percentile 90.0%

Classification

CWE
CWE-79
Status published

Affected Products (19)

apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
apache/wicket
... and 4 more

Timeline

Published Aug 29, 2011
Tracked Since Feb 18, 2026