Browse Security Advisories
Moderate Security Advisories for https://github.com/jquery/jquery from cpansa Clear Filters
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may exec...
cpan
Ukigumo-Server
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This proble...
cpan
Zonemaster-GUI
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may exec...
cpan
Zonemaster-GUI
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This proble...
cpan
Ukigumo-Server
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may exec...
cpan
Resource-Pack-jQuery
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This proble...
cpan
Plack-Debugger
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may exec...
cpan
Plack-Debugger
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This proble...
cpan
Zabbix-Reporter
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may exec...
cpan
Zabbix-Reporter
Moderate
over 6 years ago
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This proble...
cpan
Resource-Pack-jQuery
Moderate
over 7 years ago
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the nat...
cpan
Zonemaster-GUI
Moderate
over 7 years ago
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the nat...
cpan
Plack-Debugger
Moderate
over 7 years ago
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the nat...
cpan
Zabbix-Reporter
Moderate
over 7 years ago
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the nat...
cpan
Ukigumo-Server
Moderate
over 7 years ago
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the nat...
cpan
Resource-Pack-jQuery
Moderate
over 8 years ago
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for...
cpan
Ukigumo-Server
Moderate
over 8 years ago
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for...
cpan
Zonemaster-GUI
Moderate
over 8 years ago
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for...
cpan
Zabbix-Reporter
Moderate
over 8 years ago
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
cpan
Resource-Pack-jQuery
Moderate
over 8 years ago
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for...
cpan
Plack-Debugger
Moderate
over 8 years ago
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for...
cpan
Resource-Pack-jQuery
Filter by Severity
Filter by Source
CPAN Security Advisory Database
1,083
Erlang Ecosystem Foundation
266
GitHub Advisory Database
35,017
Filter by Ecosystem
Filter by Package
DBD-SQLite
14
MT
14
Yukki
11
Zonemaster-GUI
9
MySQL-Admin
9
Kossy
8
YATT-Lite
8
Zabbix-Reporter
8
UR
8
App-Netdisco
7
Stardust
7
Ukigumo-Server
7
Yote
7
Sidef
7
Plack-Debugger
7
Resource-Pack-jQuery
7
Squatting
7
SockJS
7
Yancy
7
JS-jQuery
7
DBI
4
Git-Raw
4
Git-XS
3
Win32-File-Summary
3
App-revealup
2
Sereal-Encoder
2
Sereal-Decoder
2
Alien-SVN
2
BSON-XS
2
perl
2
Win32-Printer
2
Data-RoaringBitmap-Shared
2
EasyTCP
2
Amon2-Auth-Site-LINE
1
Net-Dropbear
1
JavaScript-Duktape
1
CPAN-Checksums
1
Ukigumo-Agent
1
Data-DisjointSet-Shared
1
WWW-UsePerl-Server
1
Alien-FreeImage
1
Reverse-Proxy
1
Galileo
1
Archive-Zip
1
Net-OAuth
1
PDF-WebKit
1
Catalyst-Plugin-Static-Simple
1
LWP-Protocol-https
1
Crypt-Sodium-XS
1
Imager
1
Clipboard
1
Punk-OAuth2
1
Plack-Middleware-Bootstrap
1
HTTP-Body
1
Archive-Tar
1
HTTP-Daemon
1
Data-UUID
1
Data-Buffer-Shared
1
Alien-GCrypt
1
Nginx-Perl
1
Image-PNG-Simple
1
cppAdaptive2
1
IO-Compress-Brotli
1
JavaScript-Duktape-XS
1
IPTables-Parse
1
Perl6-Pugs
1
cppAdaptive1
1
Filter by Repository
https://github.com/jquery/jquery
90
https://github.com/twbs/bootstrap
9
https://github.com/libgit2/security
5
https://github.com/sqlite/sqlite
4
https://github.com/facebook/zstd
4
https://github.com/briandfoy/cpan-security-advisory
3
https://github.com/glennrp/libpng
3
https://github.com/perl5-dbi/dbi
3
https://github.com/jquery/jquery-ui
3
https://github.com/svaarala/duktape
2
https://github.com/Perl/perl5
2
https://github.com/jib/archive-tar-new
2
https://github.com/snapappointments/bootstrap-select
1
https://github.com/libwww-perl/lwp-protocol-https
1
https://github.com/vurtdev/Net-OAuth
1
https://github.com/perl-catalyst/Catalyst-Plugin-Static-Simple
1
https://github.com/hakimel/reveal.js
1
https://github.com/jedisct1/libsodium
1
https://github.com/angular/angular.js
1
https://github.com/libgit2/libgit2
1
https://github.com/jberger/Galileo
1
https://github.com/kingpong/perl-PDF-WebKit
1
https://github.com/redhotpenguin/perl-Archive-Zip
1
https://github.com/google/brotli
1
https://github.com/mtrmac/IPTables-Parse
1
https://github.com/libwww-perl/HTTP-Daemon
1
https://github.com/tonycoz/imager
1