cvemon logocvemon logo

Activity

Trending

CVEs

CVEs/Products/jQuery

jQuery vulnerabilities

Showing 1 - 1 of 1 CVEs

  1. CVE-2020-11023 Published Apr 29, 2020

    In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Severity
Published
CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

medium 6.9

Apr 29, 2020

TRY INTRUDER
Intruder logo

© 2026 Intruder Systems Ltd.

AboutPrivacySitemapFeeds