jquery-validation: XSS Vulnerability in jquery-validation
Published Apr 15, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.35%
Description
Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
Affected products
- Vendor n/a Product Jquery-Validation Defaultunknown
Affected
- ≥ 0, < 1.20.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Jquery-Validation | unknown | Affected
|
No data.
No data.
Red Hat Enterprise Linux 10
dotnet9.0
Fix deferred
Red Hat Enterprise Linux 8
dotnet9.0
Fix deferred
Red Hat Enterprise Linux 9
dotnet9.0
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet9.0 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | dotnet9.0 | Fix deferred | n/a |
jquery-validation
npm
Introduced 0 Fixed 1.20.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | jquery-validation | 0 | 1.20.0 |
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-3573 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2359682 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10923 Advisory
- https://github.com/advisories/GHSA-rrj2-ph5q-jxw2 Advisory
- https://github.com/jquery-validation/jquery-validation/commit/7a490d8f39bd988027568ddcf51755e1f4688902
- https://github.com/jquery-validation/jquery-validation/pull/2462
- https://nvd.nist.gov/vuln/detail/CVE-2025-3573
- https://security.snyk.io/vuln/SNYK-JS-JQUERYVALIDATION-5952285
- https://www.cve.org/CVERecord?id=CVE-2025-3573
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub