In wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display. References https://nvd.nist.gov/vuln/detail/CVE-2018-1325 https://markmail.org/message/6bxjyaolehhq7jrl https://github.com/advisories/GHSA-pjv3-rh6v-2pj8