Search CVE reports
1 – 10 of 24 results
Some fixes available 3 of 4
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an...
1 affected package
jqueryui
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jqueryui | Not affected | Fixed | Fixed | Fixed |
The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to...
3 affected packages
civicrm, jquery, node-jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
civicrm | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
jquery | Not in release | Not in release | Not affected | Not affected |
node-jquery | Not affected | Not affected | Not affected | Not affected |
jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).
1 affected package
jquery-goodies
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jquery-goodies | — | Not affected | Not affected | Not affected |
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method
3 affected packages
civicrm, jquery, node-jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
civicrm | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
jquery | Not in release | Not in release | Not affected | Not affected |
node-jquery | Not affected | Not affected | Not affected | Not affected |
Some fixes available 2 of 4
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI...
1 affected package
jqueryui
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jqueryui | — | Not affected | Fixed | Fixed |
Some fixes available 4 of 7
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in...
1 affected package
jqueryui
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jqueryui | — | Not affected | Fixed | Fixed |
Some fixes available 4 of 7
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in...
1 affected package
jqueryui
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jqueryui | — | Not affected | Fixed | Fixed |
jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names. This issue is patched in version 2.3.6.
1 affected package
jquery-minicolors
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jquery-minicolors | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the...
1 affected package
jquery
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jquery | — | — | Not affected | Not affected |
Some fixes available 4 of 5
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e....
2 affected packages
jquery, drupal7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
jquery | Not in release | Not in release | Fixed | Fixed |
drupal7 | Not in release | Not in release | Not in release | Not in release |