{"id":"CVE-2017-15719","aliases":["GHSA-pwpc-hqq2-hx2x"],"url":"https://o3.security/vulnerability/CVE-2017-15719","summary":"Cross-site Scripting in wicket-jquery-ui","details":"In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.","published":"2018-03-12T13:29:00.273Z","modified":"2026-07-08T10:55:29.468410Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent","fixedVersion":"6.28.1"},{"ecosystem":"Maven","name":"com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent","fixedVersion":"7.9.2"},{"ecosystem":"Maven","name":"com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent","fixedVersion":"8.0.0-M8.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://openmeetings.apache.org/security.html#_toc_cve-2017-15719_-_wicket_jquery_ui_xss_in_wysiwyg_e"},{"type":"ADVISORY","url":"https://github.com/sebfz1/wicket-jquery-ui/wiki#cve-2017-15719---xss-in-wysiwyg-editor"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T10:55:29.468410Z"}}