GHSA-xc66-mg8r-q6r5 · Severity: high · Ecosystem: maven — Apache Wicket vulnerable to CSRF attacks
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
Conclusion & alert: CVE-2016-6806 is rated Moderate Risk (48.3/100): CVSS High severity, with low exploitation likelihood (EPSS 0.17%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-04 | 0.12% | 0.17% | +0.04% |
| 2 | 2026-03-01 | 0.17% | 0.12% | -0.04% |
| 3 | 2026-02-04 | — | 0.17% | — |
Full EPSS history (27 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.0 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-xc66-mg8r-q6r5 · Severity: high · Ecosystem: maven — Apache Wicket vulnerable to CSRF attacks
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | wicket | 6.20.0 | cpe:2.3:a:apache:wicket:6.20.0:*:*:*:*:*:*:* |
| apache | wicket | 6.21.0 | cpe:2.3:a:apache:wicket:6.21.0:*:*:*:*:*:*:* |
| apache | wicket | 6.22.0 | cpe:2.3:a:apache:wicket:6.22.0:*:*:*:*:*:*:* |
| apache | wicket | 6.23.0 | cpe:2.3:a:apache:wicket:6.23.0:*:*:*:*:*:*:* |
| apache | wicket | 6.24.0 | cpe:2.3:a:apache:wicket:6.24.0:*:*:*:*:*:*:* |
| apache | wicket | 7.0.0 | cpe:2.3:a:apache:wicket:7.0.0:*:*:*:*:*:*:* |
| apache | wicket | 7.1.0 | cpe:2.3:a:apache:wicket:7.1.0:*:*:*:*:*:*:* |
| apache | wicket | 7.2.0 | cpe:2.3:a:apache:wicket:7.2.0:*:*:*:*:*:*:* |
| apache | wicket | 7.3.0 | cpe:2.3:a:apache:wicket:7.3.0:*:*:*:*:*:*:* |
| apache | wicket | 7.4.0 | cpe:2.3:a:apache:wicket:7.4.0:*:*:*:*:*:*:* |
| apache | wicket | 8.0.0 | cpe:2.3:a:apache:wicket:8.0.0:m1:*:*:*:*:*:* |