Skip to content
Noroxi

jqueryui records

8 published records for vendor jqueryui.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
87.5%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 21
  3. 22
  4. 24

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

8 records
  • XSS in the `of` option of the `.position()` util

    MediumCVSS 6.1Proof of conceptEPSS 41%

    jqueryui · jquery uiOct 26, 2021

  • XSS in the `altField` option of the Datepicker widget

    MediumCVSS 6.1Proof of conceptEPSS 39%

    jqueryui · jquery uiOct 26, 2021

  • CVE-2016-7103
    31Monitor

    Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 6.1No exploitEPSS 23%

    jqueryui · jquery uiMar 15, 2017

  • CVE-2010-5312
    30Monitor

    Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to i

    MediumCVSS 6.1No exploitEPSS 18%

    debian · debian linuxNov 24, 2014

  • Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and exe

    HighCVSS 7.1No exploitEPSS 1%

    Oct 17, 2024

  • XSS in `*Text` options of the Datepicker widget

    MediumCVSS 6.1No exploitEPSS 9%

    jqueryui · jquery uiOct 26, 2021

  • jQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label

    MediumCVSS 6.1Proof of conceptEPSS 3%

    jqueryui · jquery uiJul 20, 2022

  • CVE-2012-6662
    19Monitor

    Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.1

    MediumCVSS 4.3No exploitEPSS 6%

    redhat · enterprise linux desktopNov 24, 2014