CVE-2020-11023

Potential XSS vulnerability in jQuery

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.


We have discovered 8,353,176 live websites that are affected by CVE-2020-11023.

Run a Free Instant Scan




Affected Software

Product  jQuery
Category JavaScript Frameworks
Vulnerable Domains8,353,176 live websites (45% of jQuery install base)
Vulnerable Versions
  • from 1.0.3 before 3.5
Vulnerable Versions Count270 versions ( 85% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Apr 29, 2020
  • Updated - Feb 10, 2025

Website Distribution by Country

Number of websites using CVE-2020-11023
United States2,847,850 websites



Germany677,231 websites
Japan594,540 websites
Russia494,358 websites
France365,581 websites
China317,718 websites
Israel273,852 websites
GB216,036 websites
Netherlands204,308 websites
Italy198,626 websites

Website Distribution by TLD

Number of websites using CVE-2020-11023
.com3,750,032 websites
.ru428,905 websites
.de402,588 websites
.org300,274 websites
.net276,992 websites
.co.uk190,667 websites
.nl170,722 websites
.jp162,260 websites
.it157,541 websites
.fr133,581 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-11023

Top websites that are affected by CVE-2020-11023. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.***********.com United States**
********.****.br Brazil**
*******.com Singapore***
*********.com United States***
***********.com United States***
******.com United States***
******.ru Russia***
*******.*********.com United States***
*****.com China***
*****************.com United States***
See full domain list

FAQ

CVE-2020-11023 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jQuery
A total of 8,353,176 websites have been identified as vulnerable to CVE-2020-11023, based on global website indexing conducted by WebTechSurvey.
The jQuery is affected by the CVE-2020-11023 vulnerability.
jQuery versions up to 3.5 are vulnerable to CVE-2020-11023.
CVE-2020-11023 is resolved in version 3.5 of jQuery.

References