CVE-2015-7520
MEDIUMApache Wicket <1.5.15, <6.22.0, <7.2.0 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a crafted "value" attribute in a <input> element.
Scores
CVSS v3
6.1
EPSS
0.0140
EPSS Percentile
80.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
apache/wicket
< 1.5.15
Timeline
Published
Apr 12, 2016
Tracked Since
Feb 18, 2026