Vulnerabilities/

jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label

Severity:
Medium

Description

Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. If you call .checkboxradio( "refresh" ) on such a widget and the initial HTML contained encoded HTML entities, they will erroneously get decoded. This can lead to potentially executing JavaScript code.

Recommendation

Update the jquery-ui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jquery-ui
Anything's wrong? Let us know Last updated on July 21, 2025

This issue is available in SmartScanner Professional

See Pricing