CVE-2017-15719: Wicket-jQuery-UI Project Wicket-jQuery-UI

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.

Affected products

  • Wicket-jQuery-UI Project Wicket-jQuery-UI: from 6.0.0, up to and including 6.28.0; version 7.0.0 only; version 7.0.1 only; version 7.0.2 only; version 7.1.0 only; version 7.2.0 only; …

Published 2018-03-12. Last modified 2026-06-17.