Description
In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
Remediation
References
https://markmail.org/message/6bxjyaolehhq7jrl
Related Vulnerabilities
CVE-2021-46063 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2019-1003095 Vulnerability in maven package org.jenkins-ci.plugins:perfectomobile
CVE-2014-6071 Vulnerability in maven package org.webjars:jquery
CVE-2020-7615 Vulnerability in npm package fsa
CVE-2022-36893 Vulnerability in maven package org.jenkins-ci.plugins:rpmsign-plugin