Wildfly does not neutralize or incorrectly neutralizes user- controllable input before it is placed in output that is used as a web page that is served to other users.
https://blockblastpuzzle.org/ medium-priority bug? Seems like it should be higher given how it involves cross-site scripting and authenticated users. It’s a bit too risky to leave it unresolved for long. It’s great that the fix is already being worked on, but I’d love to see faster action on critical vulnerabilities like this.