Search CVE reports


Toggle filters

11 – 20 of 29 results


CVE-2020-28488

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

jqueryui

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jqueryui Not affected Not affected
Show less packages

CVE-2020-7656

Low priority
Ignored

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the...

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Not affected Not affected
Show less packages

CVE-2020-11022

Low priority

Some fixes available 5 of 6

In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may...

2 affected packages

drupal7, jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
drupal7 Not in release Not in release Not in release Not in release
jquery Not in release Not in release Fixed Fixed
Show less packages

CVE-2020-11023

High priority

Some fixes available 4 of 5

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e....

2 affected packages

jquery, drupal7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Not in release Not in release Fixed Fixed
drupal7 Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-18405

Medium priority
Ignored

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Not affected Not affected
Show less packages

CVE-2019-5428

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11358. Reason: This candidate is a duplicate of CVE-2019-11358. Notes: All CVE users should reference CVE-2019-11358 instead of this candidate. All references...

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Ignored
Show less packages

CVE-2019-11358

Low priority

Some fixes available 3 of 29

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property,...

5 affected packages

drupal7, jquery, node-jquery, mediawiki, otrs2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
drupal7 Not in release Not in release Not in release Not in release
jquery Not in release Not in release Not affected Fixed
node-jquery Not affected Not affected Not affected Vulnerable
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
otrs2 Not in release Needs evaluation Not affected Needs evaluation
Show less packages

CVE-2018-9206

High priority
Fixed

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

1 affected package

libjs-jquery-file-upload

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libjs-jquery-file-upload Fixed
Show less packages

CVE-2017-16011

Low priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6708. Reason: This candidate is a duplicate of CVE-2012-6708. Notes: All CVE users should reference CVE-2012-6708 instead of this candidate. All references...

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery Not affected
Show less packages

CVE-2016-10707

Medium priority
Not affected

jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding...

1 affected package

jquery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jquery
Show less packages