Maven package
com.googlecode.wicket-jquery-ui/wicket-jquery-ui-parent
pkg:maven/com.googlecode.wicket-jquery-ui/wicket-jquery-ui-parent
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-1325 | — | < 6.29.1 | 6.29.1 | Apr 18, 2018 | In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display. | ||
| CVE-2017-15719 | — | < 6.28.1 | 6.28.1 | Mar 12, 2018 | In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor. |
- CVE-2018-1325Apr 18, 2018affected < 6.29.1fixed 6.29.1
In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
- CVE-2017-15719Mar 12, 2018affected < 6.28.1fixed 6.28.1
In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.