cbcvebase.

Jquery Jquery-Ui vulnerabilities

7 known vulnerabilities affecting jquery/jquery-ui.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2021-41184P3MEDIUMCVSS 6.1fixed in 1.13.02021-10-26
CVE-2021-41184 [MEDIUM] CWE-79 CVE-2021-41184: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the val
ghsanvdosv
CVE-2021-41182P3MEDIUMCVSS 6.1fixed in 1.13.02021-10-26
CVE-2021-41182 [MEDIUM] CWE-79 CVE-2021-41182: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not acc
ghsanvdosv
CVE-2016-7103P3MEDIUM≥ 0, < 1.12.02017-10-24
CVE-2016-7103 [MEDIUM] CWE-79 jQuery-UI vulnerable to Cross-site Scripting in dialog closeText jQuery-UI vulnerable to Cross-site Scripting in dialog closeText Affected versions of `jquery-ui` are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the `closeText` parameter in the `dialog` function. jQuery-UI is a library for manipulating UI elements via jQuery. Version 1.11.4 has a cross site scripting (XSS) vulnerability in the `closeText
ghsaosv
CVE-2021-41183P3MEDIUMCVSS 6.1fixed in 1.13.02021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
ghsanvdosv
CVE-2010-5312P3MEDIUM≥ 1.7.0, < 1.10.02017-10-24
CVE-2010-5312 [MEDIUM] CWE-79 Cross-site Scripting in jquery-ui Cross-site Scripting in jquery-ui Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
ghsaosv
CVE-2022-31160P4MEDIUMCVSS 6.1fixed in 1.13.22022-07-20
CVE-2022-31160 [MEDIUM] CWE-79 CVE-2022-31160: jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "r
ghsanvdosv
CVE-2012-6662P4MEDIUM≥ 0, < 1.10.02017-10-24
CVE-2012-6662 [MEDIUM] CWE-79 jquery-ui Tooltip widget vulnerable to XSS jquery-ui Tooltip widget vulnerable to XSS Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.
ghsaosv
Jquery Jquery-Ui vulnerabilities | cvebase