Cross-site scripting in Apache Wicket - CVE-2026-66390
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script code in a user's browser.
The vulnerability exists due to improper neutralization of input during web page generation in Link URL handling when rendering crafted Link URL strings into a JavaScript sequence. A remote attacker can supply a specially crafted Link URL string to execute arbitrary script code in a user's browser.