Description
Passing HTML from untrusted sources - even after sanitizing it - to one of jQuery’s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.
Recommendation
Update the jquery package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.12.0, < 3.5.0
- Patched version(s): 3.5.0
References
Could your website be exposed too?
SmartScanner can check your website for Potential XSS vulnerability in jQuery - jquery and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Potential XSS vulnerability in jQuery - CVE-2020-11023
- CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover - CVE-2024-43411
- Potential XSS in jQuery dependency in Mirador - Vulnerability
- CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS - CVE-2026-26028
You might also like:
See something that needs correcting? Let us knowUpdated July 09, 2026


