In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
We have discovered 7,099,257 live websites that are affected by CVE-2020-11023.
| Product | |
| Category | JavaScript Frameworks |
| Vulnerable Domains | 7,099,257 live websites (42% of jQuery install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 269 versions ( 86% of all versions) |
| 2,165,231 websites | |
| 529,414 websites | |
| 462,708 websites | |
| 449,488 websites | |
| 310,793 websites | |
| 289,979 websites | |
| 282,786 websites | |
| 216,007 websites | |
| 180,138 websites | |
| 179,354 websites |
| .com | 3,171,206 websites |
| .ru | 375,179 websites |
| .de | 340,314 websites |
| .org | 256,638 websites |
| .net | 231,388 websites |
| .co.uk | 162,358 websites |
| .nl | 147,138 websites |
| .it | 129,757 websites |
| .jp | 128,480 websites |
| .fr | 109,424 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.***********.com | ** | ||
| ********.****.br | ** | ||
| *********.com | *** | ||
| *******.com | *** | ||
| *********.com | *** | ||
| ***********.com | *** | ||
| ******.com | *** | ||
| ******.ru | *** | ||
| *******.*********.com | *** | ||
| *****************.com | *** |
FAQ