In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.
{
"versions": [
{
"introduced": "6.0.0"
},
{
"last_affected": "6.28.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.0-milestone3"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.0-milestone4"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.0-milestone5"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.0-milestone6"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "7.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "7.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "7.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.7.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.9.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone1"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone1\\.1"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone2"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone3"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone4"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone4\\.1"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone5"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone6"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone7"
},
{
"introduced": "0"
},
{
"last_affected": "8.0.0-milestone8"
},
{
"introduced": "0"
},
{
"last_affected": "7.9.1"
}
]
}