athlon1600/youtube-downloader
:tv: PHP based alternative to youtube-dl and yt-dlp. Active and frequently updated! :star:
Activity
- Latest release
- 3mo ago
- Total releases
- 23
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- 933
Details
- License
- MIT
- First release
- Dec 27, 2016
| Version | Released | |
|---|---|---|
v4.0.1
patch
| ||
v4.0.0
major
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.1.2
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.1.1
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.1.0
minor
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.2
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.1
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.1.2
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v3.0.0
major
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.1.1
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.1.0
minor
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.9
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.8
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.7
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.6
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.5
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.4
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.3
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.2
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.1
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.0.0
major
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.1
patch
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.0
initial
1 CVE
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
v1.0.0
v1.0.1
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
+ 10 more Show less
v2.1.0
v2.1.1
v2.1.2
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v4.0.0
Fixed in
4.0.1
References
Updated Sep 10, 2026 · Source: OSV.dev |