A vulnerability classified as problematic has been found in Apache Wicket up to 9.23.0/10.9.0. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting.

This vulnerability is registered as CVE-2026-66390. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.