GHSA-jpcq-cgw6-v4j6 · Severity: medium · Ecosystem: npm — Potential XSS vulnerability in jQuery
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Conclusion & alert: CVE-2020-11023 is rated Critical Active Threat (81.6/100): CVSS Medium severity, with high exploitation likelihood (EPSS 34.66%, 97th percentile). Core evidence: CISA KEV confirms active exploitation (added 2025-01-23) affecting JQuery / JQuery. cross-site scripting (CWE-79) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: JQuery Cross-Site Scripting (XSS) Vulnerability · CISA KEV detail
: 2025-01-23
: 2025-02-13
: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 49767 | exploit_db | edb | 2021-04-14 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 43.90% | 34.66% | -9.24% |
| 2 | 2026-05-12 | 58.21% | 43.90% | -14.31% |
| 3 | 2026-05-08 | — | 58.21% | — |
Full EPSS history (96 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.9 | 3.1 | MEDIUM |
|
1.6 | 4.7 | [email protected] |
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-jpcq-cgw6-v4j6 · Severity: medium · Ecosystem: npm — Potential XSS vulnerability in jQuery
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2020-11023: 2 source package rows (cacti, drupal7); 12 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 12, open 0. | https://security.alpinelinux.org/vuln/CVE-2020-11023 |
debian
|
not yet assigned | CVE-2020-11023 not yet assigned priority: Debian including 2 source packages (node-jquery, otrs2), 6 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 6. | https://security-tracker.debian.org/tracker/CVE-2020-11023 |
gentoo
|
normal | CVE-2020-11023: 1 GLSA(s) (202007-03), 2 atom(s) (net-analyzer/cacti, net-analyzer/cacti-spine); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2020-11023 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-11023 |
suse
|
medium | CVE-2020-11023 severity moderate: SUSE including 15 source package names (3.3.2-2.3:testng-7.4.0-150200.3.4.3, groovy-testng-2.4.21-150200.3.7.4, …), 170 product×package rows across 51 product lines (Container containers/apache-pulsar, HPE Helion OpenStack 8, … (51 product lines)): Known Not Affected 129, Fixed 41. | https://www.suse.com/security/cve/CVE-2020-11023/ |
ubuntu
|
high | CVE-2020-11023 high priority: Ubuntu including 2 source packages (drupal7, jquery), 31 status rows across 16 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, trusty, upstream, xenial): DNE 22, released 4, needs-triage 2, not-affected 2, ignored 1. | https://ubuntu.com/security/CVE-2020-11023 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| jquery | jquery | >= 1.0.3, < 3.5.0 | cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| fedoraproject | fedora | 32 | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
| fedoraproject | fedora | 33 | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
| drupal | drupal | >= 7.0, < 7.70 | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
| drupal | drupal | >= 8.7.0, < 8.7.14 | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
| drupal | drupal | >= 8.8.0, < 8.8.6 | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
| oracle | application_express | < 20.2 | cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:* |
| oracle | application_testing_suite | 13.3.0.1 | cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* |
| oracle | banking_enterprise_collections | >= 2.7.0, <= 2.8.0 | cpe:2.3:a:oracle:banking_enterprise_collections:*:*:*:*:*:*:*:* |
| oracle | banking_platform | >= 2.4.0, <= 2.10.0 | cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:* |
| oracle | blockchain_platform | < 21.1.2 | cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* |
| oracle | blockchain_platform | 21.1.2 | cpe:2.3:a:oracle:blockchain_platform:21.1.2:*:*:*:*:*:*:* |
| oracle | business_intelligence | 5.9.0.0.0 | cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:* |
| oracle | communications_analytics | 12.1.1 | cpe:2.3:a:oracle:communications_analytics:12.1.1:*:*:*:*:*:*:* |
| oracle | communications_eagle_application_processor | >= 16.1.0, <= 16.4.0 | cpe:2.3:a:oracle:communications_eagle_application_processor:*:*:*:*:*:*:*:* |
| oracle | communications_element_manager | 8.1.1 | cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:* |
| oracle | communications_element_manager | 8.2.0 | cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:* |
| oracle | communications_element_manager | 8.2.1 | cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:* |
| oracle | communications_interactive_session_recorder | >= 6.1, <= 6.4 | cpe:2.3:a:oracle:communications_interactive_session_recorder:*:*:*:*:*:*:*:* |
| oracle | communications_operations_monitor | >= 4.1, <= 4.3 | cpe:2.3:a:oracle:communications_operations_monitor:*:*:*:*:*:*:*:* |
| oracle | communications_operations_monitor | 3.4 | cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:* |
| oracle | communications_services_gatekeeper | 7.0 | cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:* |
| oracle | communications_session_report_manager | 8.1.1 | cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:* |
| oracle | communications_session_report_manager | 8.2.0 | cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:* |
| oracle | communications_session_report_manager | 8.2.1 | cpe:2.3:a:oracle:communications_session_report_manager:8.2.1:*:*:*:*:*:*:* |
| oracle | communications_session_route_manager | 8.1.1 | cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:* |
| oracle | communications_session_route_manager | 8.2.0 | cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:* |
| oracle | communications_session_route_manager | 8.2.1 | cpe:2.3:a:oracle:communications_session_route_manager:8.2.1:*:*:*:*:*:*:* |
| oracle | financial_services_regulatory_reporting_for_de_nederlandsche_bank | 8.0.4 | cpe:2.3:a:oracle:financial_services_regulatory_reporting_for_de_nederlandsche_bank:8.0.4:*:*:*:*:*:*:* |
| oracle | financial_services_revenue_management_and_billing_analytics | 2.7 | cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7:*:*:*:*:*:*:* |
| oracle | financial_services_revenue_management_and_billing_analytics | 2.8 | cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8:*:*:*:*:*:*:* |
| oracle | health_sciences_inform | 6.3.0 | cpe:2.3:a:oracle:health_sciences_inform:6.3.0:*:*:*:*:*:*:* |
| oracle | healthcare_translational_research | 3.2.1 | cpe:2.3:a:oracle:healthcare_translational_research:3.2.1:*:*:*:*:*:*:* |
| oracle | healthcare_translational_research | 3.3.1 | cpe:2.3:a:oracle:healthcare_translational_research:3.3.1:*:*:*:*:*:*:* |
| oracle | healthcare_translational_research | 3.3.2 | cpe:2.3:a:oracle:healthcare_translational_research:3.3.2:*:*:*:*:*:*:* |
| oracle | healthcare_translational_research | 3.4.0 | cpe:2.3:a:oracle:healthcare_translational_research:3.4.0:*:*:*:*:*:*:* |
| oracle | hyperion_financial_reporting | 11.1.2.4 | cpe:2.3:a:oracle:hyperion_financial_reporting:11.1.2.4:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_orchestrator | < 9.2.5.0 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:*:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.5.0 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* |
| oracle | oss_support_tools | < 2.12.41 | cpe:2.3:a:oracle:oss_support_tools:*:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_human_capital_management_resources | 9.2 | cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_resources:9.2:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 16.2, <= 16.2.11 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 17.12.0, <= 17.12.7 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 18.8.0, <= 18.8.9 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | primavera_gateway | >= 19.12.0, <= 19.12.4 | cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
| oracle | rest_data_services | 11.2.0.4 | cpe:2.3:a:oracle:rest_data_services:11.2.0.4:*:*:*:-:*:*:* |
| oracle | rest_data_services | 12.1.0.2 | cpe:2.3:a:oracle:rest_data_services:12.1.0.2:*:*:*:-:*:*:* |
| oracle | rest_data_services | 12.2.0.1 | cpe:2.3:a:oracle:rest_data_services:12.2.0.1:*:*:*:-:*:*:* |
| oracle | rest_data_services | 18c | cpe:2.3:a:oracle:rest_data_services:18c:*:*:*:-:*:*:* |
| oracle | rest_data_services | 19c | cpe:2.3:a:oracle:rest_data_services:19c:*:*:*:-:*:*:* |
| oracle | siebel_mobile | <= 20.12 | cpe:2.3:a:oracle:siebel_mobile:*:*:*:*:*:*:*:* |
| oracle | storagetek_acsls | 8.5.1 | cpe:2.3:a:oracle:storagetek_acsls:8.5.1:*:*:*:*:*:*:* |
| oracle | storagetek_tape_analytics_sw_tool | 2.3.1 | cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3.1:*:*:*:*:*:*:* |
| oracle | webcenter_sites | 12.2.1.3.0 | cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | webcenter_sites | 12.2.1.4.0 | cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.1.3.0.0 | cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.3.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.4.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 14.1.1.0.0 | cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* |
| netapp | h300s_firmware | — | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
| netapp | h500s_firmware | — | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
| netapp | h700s_firmware | — | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
| netapp | h300e_firmware | — | cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:* |
| netapp | h500e_firmware | — | cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:* |
| netapp | h700e_firmware | — | cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:* |
| netapp | h410s_firmware | — | cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* |
| netapp | h410c_firmware | — | cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
| netapp | cloud_backup | — | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* |
| netapp | cloud_insights_storage_workload_security_agent | — | cpe:2.3:a:netapp:cloud_insights_storage_workload_security_agent:-:*:*:*:*:*:*:* |
| netapp | hci_baseboard_management_controller | — | cpe:2.3:a:netapp:hci_baseboard_management_controller:-:*:*:*:*:*:*:* |
| netapp | max_data | — | cpe:2.3:a:netapp:max_data:-:*:*:*:*:*:*:* |
| netapp | oncommand_insight | — | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
| netapp | oncommand_system_manager | >= 3.0, <= 3.1.3 | cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* |
| netapp | snap_creator_framework | — | cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:* |
| netapp | snapcenter_server | — | cpe:2.3:a:netapp:snapcenter_server:-:*:*:*:*:*:*:* |