Search CVE reports
11 – 20 of 24 results
CVE-2020-11023
Low priorityIn jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e....
2 affected packages
drupal7, jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
jquery | Not in release | Not in release | Vulnerable | Vulnerable | Not affected |
CVE-2018-18405
Medium priority** DISPUTED ** jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry.
1 affected packages
jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jquery | — | — | Not affected | Not affected | Not affected |
CVE-2019-11358
Low priorityjQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property,...
5 affected packages
drupal7, jquery, mediawiki, node-jquery, otrs2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
jquery | Not in release | Not in release | Not affected | Vulnerable | Vulnerable |
mediawiki | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
node-jquery | Not affected | Not affected | Not affected | Vulnerable | Vulnerable |
otrs2 | Not in release | Needs evaluation | Not affected | Needs evaluation | Needs evaluation |
CVE-2018-9206
High priorityUnauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
1 affected packages
libjs-jquery-file-upload
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libjs-jquery-file-upload | — | — | — | Fixed | Not in release |
CVE-2016-10707
Medium priorityjQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding...
1 affected packages
jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jquery | — | — | — | — | Not affected |
CVE-2015-9251
Low priorityjQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
1 affected packages
jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jquery | — | — | Not affected | Not affected | Ignored |
CVE-2012-6708
Low priorityjQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input...
1 affected packages
jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jquery | Not in release | Not in release | Not affected | Not affected | Not affected |
CVE-2014-6071
Low priorityjQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside after.
1 affected packages
jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jquery | — | — | — | — | — |
CVE-2016-7103
Medium prioritySome fixes available 2 of 6
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
1 affected packages
jqueryui
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jqueryui | — | Not affected | Not affected | Not affected | Fixed |
CVE-2015-1840
Medium priorityjquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of...
1 affected packages
ruby-jquery-rails
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-jquery-rails | — | — | — | Not affected | Not affected |