← Back to CVE List
Vulnerability Intelligence Report
Potential XSS vulnerability in jQuery

CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
6.9
MEDIUM
Exploitability:1.7
Impact Score:4.8
EPSS Probability:83.83%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-79 ↗CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected Products & Versions

Vendor Product Affected Versions
jquery jQuery >= 1.0.3, < 3.5.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
83.830%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2020-03-30T00:00:00
Published2020-04-29T00:00:00
Last Updated2025-10-21T23:35:45

LINK COPIED TO CLIPBOARD