jquery-rails
This gem provides jQuery and the jQuery-ujs driver for your Rails 4+ application.
Activity
- Latest release
- 10mo ago
- Total releases
- 79
- Cadence
- ~26 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Aug 16, 2010
| Version | Released | |
|---|---|---|
4.6.1
patch
| ||
4.6.0
minor
| ||
4.5.1
patch
| ||
4.5.0
minor
| ||
4.4.0
minor
| ||
4.3.4
patch
2 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.3.5
patch
2 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.3.2
patch
3 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.3.3
patch
3 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.1.5
patch
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
4.3.1
patch
3 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.3.0
minor
3 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.2.2
patch
3 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.2.1
patch
3 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.2.0
minor
3 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.1.1
patch
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
4.1.0
minor
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
3.1.4
patch
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
4.0.5
patch
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
4.0.4
patch
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
3.1.3
patch
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
4.0.3
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
4.0.2
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
4.0.1
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
4.0.0
major
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
4.0.0.beta1
pre
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
4.0.0.beta2
pre
4 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev | ||
3.1.2
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
3.1.1
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
3.1.0
minor
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
3.0.4
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
3.0.3
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
3.0.2
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
3.0.1
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
3.0.0
major
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.3.0
minor
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.2.2
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.2.1
patch
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.2.0
minor
5 CVEs
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.1.4
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.1.3
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.1.2
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.1.1
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.1.0
minor
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.0.3
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.0.2
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
2.0.1
major
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
1.0.19
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
1.0.18
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
1.0.17
patch
7 CVEs
CVE-2012-6708
GHSA-2pqj-h3vj-pqgw
Sep 01, 2020
Cross-Site Scripting in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of Proof of Concept
RecommendationUpdate to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Mar 08, 2024 · Source: OSV.dev
CVE-2020-7656
GHSA-q4m3-2j7h-f7xw
SNYK-JS-JQUERY-569619
May 20, 2020
Cross-Site Scripting in jquery
Medium
Network
Low
None
Versions of RecommendationUpgrade to version 1.9.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 28 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2020-11023
GHSA-jpcq-cgw6-v4j6
BIT-drupal-2020-11023
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML containing PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround this issue without upgrading, use DOMPurify with its Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-11022
GHSA-gxr4-xjj5-5px2
BIT-drupal-2020-11022
Apr 29, 2020
Potential XSS vulnerability in jQuery
6.9
/ 10
Medium
Network
High
None
Required
Changed
High
Low
None
ImpactPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. PatchesThis problem is patched in jQuery 3.5.0. WorkaroundsTo workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround. Referenceshttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/ For more informationIf you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 62 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
Fixed in
4.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11358
GHSA-6c3j-c64m-qhgq
DRUPAL-CORE-2019-006
PYSEC-2026-628
SNYK-JS-JQUERY-174006
Apr 26, 2019
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 60 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
Fixed in
4.3.4
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-9251
GHSA-rmxg-73gg-4p98
Jan 22, 2018
Cross-Site Scripting (XSS) in jquery
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Affected versions of RecommendationUpdate to version 3.0.0 or later. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 53 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
4.0.0
4.0.0.beta1
4.0.0.beta2
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
Fixed in
4.2.0
References
Updated Mar 10, 2024 · Source: OSV.dev
CVE-2015-1840
GHSA-4whc-pp4x-9pf3
Oct 24, 2017
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
Medium
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value. Affected versions
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.0
+ 44 more Show less
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.rc
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.0.2
4.0.3
Fixed in
3.1.3
4.0.4
References
Updated Feb 03, 2026 · Source: OSV.dev |