What is CVE-2026-66390?
This CVE identifies a Cross-site Scripting (XSS) vulnerability in Apache Wicket web framework. Affected versions include 9.0.0 through 9.23.0 and 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0 to mitigate the issue.
Azərbaycanca: Bu CVE Apache Wicket veb freymvorkunda aşkarlanmış Cross-site Scripting (XSS) zəifliyidir. 9.0.0-9.23.0 və 10.0.0-10.9.0 versiyaları təsirlənir. İstifadəçilərə bu problemi aradan qaldıran 10.10.0 versiyasına yüksəltmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Apache
FAQ2
Which software product is affected by CVE-2026-66390?
This CVE identifies a Cross-site Scripting (XSS) vulnerability in the Apache Wicket web framework.
To which version should users upgrade to mitigate CVE-2026-66390?
Users are recommended to upgrade to Apache Wicket version 10.10.0 to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.