Skip to main content
CISA Known Exploited Vulnerabilities

JQuery Cross-Site Scripting (XSS) Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2025-01-23
Remediation due
2025-02-13

Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA notes
This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6 ; https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2020-11023

Description

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Severity

CVSS 3.1 · CNA6.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impactpartial

Affected Products

VendorProductAffected versions
jqueryjQuery
>= 1.0.3, < 3.5.0

References

66 Links
Mailing lists
Other references

Record Details

Published
2020-04-29
Last updated
2025-10-21
Assigner (CNA)
GitHub_M
Credited to
-

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.