CVE-2020-11022

jQuery has a potential XSS vulnerability

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.


We have discovered 3,491,397 live websites that are affected by CVE-2020-11022.

Run a Free Instant Scan




Affected Software

Product  jQuery
Category JavaScript Frameworks
Vulnerable Domains3,491,397 live websites (21% of jQuery install base)
Vulnerable Versions
  • from 1.12 through 3.5
Vulnerable Versions Count85 versions ( 27% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Apr 29, 2020
  • Updated - Apr 13, 2026

Website Distribution by Country

Number of websites using CVE-2020-11022
United States977,723 websites



Germany271,146 websites
Russia231,034 websites
Japan215,053 websites
Israel157,110 websites
France156,805 websites
GB111,016 websites
Netherlands106,267 websites
Italy100,786 websites
China88,642 websites

Website Distribution by TLD

Number of websites using CVE-2020-11022
.com1,508,192 websites
.ru186,917 websites
.de165,196 websites
.org125,434 websites
.net99,483 websites
.nl81,029 websites
.co.uk78,932 websites
.it73,384 websites
.fr62,051 websites
.jp60,907 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-11022

Top websites that are affected by CVE-2020-11022. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.***********.com United States**
********.****.br Brazil**
*******.com Singapore***
***********.com Ireland***
******.com United States***
****.br Brazil***
*****.******.com United States***
**********.com United States***
*********.com Canada***
*******.com United States***
See full domain list

FAQ

CVE-2020-11022 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jQuery
A total of 3,491,397 websites have been identified as vulnerable to CVE-2020-11022, based on global website indexing conducted by WebTechSurvey.
The jQuery is affected by the CVE-2020-11022 vulnerability.
jQuery versions up to 3.5 are vulnerable to CVE-2020-11022.
CVE-2020-11022 is resolved in version 3.5 of jQuery.

References