cbcvebase.
CVE-2020-11022
published 2020-04-29

CVE-2020-11022: In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods…

PriorityP184medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
99.02%
99.9th percentile
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Affected

130 ranges· showing 25
VendorProductVersion rangeFixed in
athlon1600youtube-downloader0 – 4.0.0
componentsjquery>= 1.12.0 < 3.5.03.5.0
componentsjquery>= 1.2.0 < 3.5.03.5.0
debiandebian_linux
debiannode-jquery< node-jquery 3.5.0+dfsg-2 (bookworm)node-jquery 3.5.0+dfsg-2 (bookworm)
debianotrs2< node-jquery 3.5.0+dfsg-2 (bookworm)node-jquery 3.5.0+dfsg-2 (bookworm)
drupalcore>= 8.0.0 < 8.7.148.7.14
drupalcore>= 8.8.0 < 8.8.68.8.6
drupaldrupal>= 7.0 < 7.707.70
drupaldrupal>= 8.7.0 < 8.7.148.7.14
drupaldrupal>= 8.8.0 < 8.8.68.8.6
drupaldrupal_core
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
jqueryjquery
jqueryjquery>= 0 < 1.7.2+dfsg-2ubuntu1+esm11.7.2+dfsg-2ubuntu1+esm1
jqueryjquery>= 0 < 1.11.3+dfsg-4ubuntu0.1~esm11.11.3+dfsg-4ubuntu0.1~esm1
jqueryjquery>= 0 < 3.2.1-1ubuntu0.1~esm13.2.1-1ubuntu0.1~esm1
jqueryjquery>= 1.12.0 < 3.5.03.5.0
jqueryjquery>= 1.12.0 < 3.5.03.5.0
jqueryjquery>= 1.2 < 3.5.03.5.0
jqueryjquery>= 1.2.0 < 3.5.03.5.0
jqueryjquery>= 1.2.0 < 3.5.03.5.0
maximebfdebugbar>= 0 < 1.19.01.19.0

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor application URL query strings and web form inputs for injected JavaScript payloads targeting applications running jQuery <= 3.5.0
  • Use static code analysis / dependency scanning to identify jQuery versions >= 1.2 and < 3.5.0 in web application dependencies as a detection/inventory signal
  • In SIEM, create queries to flag suspicious reflected XSS activity (anomalous JavaScript execution) originating from untrusted domains against endpoints running vulnerable jQuery versions
  • ·CVE-2020-11022 affects jQuery versions >= 1.2 and < 3.5.0; the NVD entry scopes the vulnerable range as 'starting with 1.12.0 and before 3.5.0' while other sources (exploit-db, CISA advisories) cite >= 1.2 — verify the exact lower bound against your deployed version
  • ·The Huntress source incorrectly states the fixed version is jQuery 3.5.1; the official patch is jQuery 3.5.0 per NVD. Ensure remediation targets >= 3.5.0.
  • ·No known public exploitation specifically targeting this vulnerability has been reported to CISA as of the Hitachi Energy advisory (July 2025); risk context should be weighed accordingly for ICS/OT environments

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vulncheck6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_oracle6.1MEDIUM
vendor_ubuntu6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.