Exposição de jQuery

JavaScript libraries
98
score de exposição
5.869.961
sites usam
1
em exploração
0
críticos
Análise Vexday

jQuery acumula 54 CVEs catalogadas, com predominância de CWE-79 (Cross-Site Scripting), o que reflete o perfil histórico da biblioteca como superfície de ataque para injeção de scripts em aplicações web. Apesar de nenhuma CVE ser classificada como crítica, a taxa de exploração ativa está ACIMA da média geral do catálogo — 4,1 vezes superior —, indicando que vulnerabilidades da biblioteca são alvo concreto de agentes maliciosos, não apenas teórico. A CVE mais perigosa em exploração ativa, CVE-2020-11023, apresenta EPSS de 0,84, sinalizando alta probabilidade de exploração observada na prática, e merece atenção imediata em ambientes que ainda executam versões afetadas. O surgimento de 4 novas CVEs nos últimos 90 dias reforça que a superfície de risco permanece ativa, tornando a atualização e o inventário de dependências jQuery uma prioridade operacional contínua.

CVEs

54 resultados
CVE-2020-11023MEDIUMPotential XSS vulnerability in jQueryEPSS 83.8%KEVCVE-2020-11022MEDIUMjQuery has a potential XSS vulnerabilityEPSS 99.0%CVE-2018-9206Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0EPSS 97.1%CVE-2021-41184MEDIUMXSS in the `of` option of the `.position()` utilEPSS 40.8%CVE-2021-41182MEDIUMXSS in the `altField` option of the Datepicker widgetEPSS 39.4%CVE-2021-41183MEDIUMXSS in `*Text` options of the Datepicker widgetEPSS 7.9%CVE-2020-7656jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTMLEPSS 6.3%CVE-2021-20086Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to injEPSS 6.1%CVE-2021-20083Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicEPSS 4.2%CVE-2018-9207Arbitrary file upload in jQuery Upload File <= 4.0.2EPSS 3.5%CVE-2021-21252MEDIUMRegular expression denial of service in jquery-validationEPSS 3.4%CVE-2018-9208Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1BetaEPSS 2.7%CVE-2022-31160MEDIUMjQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text labelEPSS 2.5%CVE-2018-0645MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.EPSS 2.4%CVE-2021-20087Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user toEPSS 2.1%CVE-2022-31147HIGHjquery-validation ReDoS in url2 due to incomplete fix of CVE-2021-43306EPSS 2.0%CVE-2021-43306MEDIUMExponential ReDoS in jquery-validationEPSS 1.4%CVE-2021-20084Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious usEPSS 1.4%CVE-2017-16045`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2021-43862LOWSelf XSS on user inputEPSS 1.0%