Description
In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
Remediation
References
https://markmail.org/message/6bxjyaolehhq7jrl
Related Vulnerabilities
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js
CVE-2022-23307 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2021-27185 Vulnerability in npm package samba-client
CVE-2021-39154 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2019-11405 Vulnerability in maven package org.openapitools:openapi-generator-project