In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
We have discovered 3,491,397 live websites that are affected by CVE-2020-11022.
| Product | |
| Category | JavaScript Frameworks |
| Vulnerable Domains | 3,491,397 live websites (21% of jQuery install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 85 versions ( 27% of all versions) |
| 977,723 websites | |
| 271,146 websites | |
| 231,034 websites | |
| 215,053 websites | |
| 157,110 websites | |
| 156,805 websites | |
| 111,016 websites | |
| 106,267 websites | |
| 100,786 websites | |
| 88,642 websites |
| .com | 1,508,192 websites |
| .ru | 186,917 websites |
| .de | 165,196 websites |
| .org | 125,434 websites |
| .net | 99,483 websites |
| .nl | 81,029 websites |
| .co.uk | 78,932 websites |
| .it | 73,384 websites |
| .fr | 62,051 websites |
| .jp | 60,907 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.***********.com | ** | ||
| ********.****.br | ** | ||
| *******.com | *** | ||
| ***********.com | *** | ||
| ******.com | *** | ||
| ****.br | *** | ||
| *****.******.com | *** | ||
| **********.com | *** | ||
| *********.com | *** | ||
| *******.com | *** |
FAQ