← Database

CVE-2026-76985

MEDIUM CVSS: 5.4 Published: 2026-08-31 Modified: 2026-09-01

Description

Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a Palette, escapes the id and the display value of each option according to the escape-model-strings setting, and wrote the attribute names and values returned by getAdditionalAttributes into the

Affected Platforms

Apache Wicket

Weakness Type

CWE-79

References