jquery records
11 published records for vendor jquery.
Researcher profile
- Entered KEV
- 1 · 9.1%
- Weaponized
- 1 · 9.1%
- Pre-auth RCE
- 0
- With a fix record
- 72.7%
- Median publish → KEV
- 1730 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-674 Uncontrolled Recursion1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
79This week | CVE-2020-11023Weaponized | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Medium6.1 | KEV | 84.9% | Apr 29, 2020 |
54Plan | CVE-2020-11022Proof of concept | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Medium6.1 | — | 99.2% | Apr 29, 2020 |
50Plan | CVE-2019-11358Proof of concept | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Medium6.1 | — | 87.2% | Apr 19, 2019 |
33Monitor | CVE-2015-9251Proof of concept | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType ojquery · jquery · CWE-79 | Medium6.1 | — | 29.7% | Jan 18, 2018 |
31Monitor | CVE-2016-10707No exploit | jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names.jquery · jquery · CWE-674 | High7.5 | — | 2.9% | Jan 18, 2018 |
27Monitor | CVE-2012-6708Proof of concept | jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks.jquery · jquery · CWE-79 | Medium6.1 | — | 8.6% | Jan 18, 2018 |
26Monitor | CVE-2020-7656Proof of concept | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.jquery · jquery · CWE-79 | Medium6.1 | — | 6.3% | May 19, 2020 |
25Monitor | CVE-2014-6071No exploit | jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside aftejquery · jquery · CWE-79 | Medium6.1 | — | 2.3% | Jan 16, 2018 |
24Monitor | CVE-2018-18405No exploit | jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.jquery · jquery · CWE-79 | Medium6.1 | — | 1.7% | Apr 22, 2020 |
23Monitor | CVE-2011-4969No exploit | Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to injjquery · jquery · CWE-79 | Medium4.3 | — | 19.2% | Mar 8, 2013 |
21Monitor | CVE-2007-2379No exploit | The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attjquery · jquery · CWE-200 | Medium5.0 | — | 2.8% | Apr 30, 2007 |
- CVE-2020-1102379This week
Potential XSS vulnerability in jQuery
MediumCVSS 6.1KEVWeaponizedEPSS 85%jquery · jqueryApr 29, 2020
- CVE-2020-1102254Plan
jQuery has a potential XSS vulnerability
MediumCVSS 6.1Proof of conceptEPSS 99%jquery · jqueryApr 29, 2020
- CVE-2019-1135850Plan
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
MediumCVSS 6.1Proof of conceptEPSS 87%jquery · jqueryApr 19, 2019
- CVE-2015-925133Monitor
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType o
MediumCVSS 6.1Proof of conceptEPSS 30%jquery · jqueryJan 18, 2018
- CVE-2016-1070731Monitor
jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names.
HighCVSS 7.5No exploitEPSS 3%jquery · jqueryJan 18, 2018
- CVE-2012-670827Monitor
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks.
MediumCVSS 6.1Proof of conceptEPSS 9%jquery · jqueryJan 18, 2018
- CVE-2020-765626Monitor
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.
MediumCVSS 6.1Proof of conceptEPSS 6%jquery · jqueryMay 19, 2020
- CVE-2014-607125Monitor
jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside afte
MediumCVSS 6.1No exploitEPSS 2%jquery · jqueryJan 16, 2018
- CVE-2018-1840524Monitor
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.
MediumCVSS 6.1No exploitEPSS 2%jquery · jqueryApr 22, 2020
- CVE-2011-496923Monitor
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj
MediumCVSS 4.3No exploitEPSS 19%jquery · jqueryMar 8, 2013
- CVE-2007-237921Monitor
The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote att
MediumCVSS 5.0No exploitEPSS 3%jquery · jqueryApr 30, 2007