Cross-site scripting in Apache Wicket - CVE-2026-42509
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in web page generation when processing crafted strings in JavaScript sequences. A remote attacker can supply a specially crafted string to execute arbitrary script code in a victim's browser.