jQuery / jQuery
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-7656 | jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces | MEDIUM | 5.3 | May 19, 2020 |
| CVE-2020-11023 KEV | Potential XSS vulnerability in jQuery | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2020-11022 | jQuery has a potential XSS vulnerability | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2018-18405 | jquery: crafted onerror attribute of an IMG element could result in XSS | MEDIUM | 6.1 | Apr 22, 2020 |
| CVE-2019-11358 | jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection | MEDIUM | 6.1 | Apr 19, 2019 |
| CVE-2016-10707 | jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased na… | HIGH | 7.5 | Jan 18, 2018 |
| CVE-2015-9251 | jquery: Cross-site scripting via cross-domain ajax requests | MEDIUM | 6.1 | Jan 18, 2018 |
| CVE-2012-6708 | js-jquery: XSS via improper selector detection | MEDIUM | 6.8 | Jan 18, 2018 |
| CVE-2014-6071 | jQuery: cross-site scripting flaw | MEDIUM | 6.1 | Jan 16, 2018 |
| CVE-2011-4969 | jquery: Cross-site scripting (XSS) via $(location.hash) and $(#<tag>) | MEDIUM | 4.3 | Mar 8, 2013 |
| CVE-2007-2379 | The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain th… | MEDIUM | 5.0 | Apr 30, 2007 |
Showing 1 to 11 of 11 CVEs