Description
In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
Remediation
References
https://markmail.org/message/6bxjyaolehhq7jrl
Related Vulnerabilities
CVE-2020-26870 Vulnerability in maven package org.webjars.bower:dompurify
CVE-2022-33140 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-framework
CVE-2020-7625 Vulnerability in npm package op-browser
CVE-2019-9737 Vulnerability in maven package org.webjars.npm:editor.md
CVE-2021-25646 Vulnerability in maven package org.apache.druid:druid-core