CVE-2018-1325: Wicket-jQuery-UI Project Wicket-jQuery-UI

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.

Affected products

  • Wicket-jQuery-UI Project Wicket-jQuery-UI: from 6.0.0, up to and including 6.29.0; from 7.0.1, up to and including 7.10.1; version 7.0.0 only; version 8.0.0 only

Published 2018-04-18. Last modified 2026-06-17.