AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-11976

HIGH · CVSS 7.5 EPSS 3.76%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-08-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-11976
Severity
HIGH
CVSS
7.5
EPSS
3.76%
Apache

Original NVD Description

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5