CVE-2020-11023

Potential XSS vulnerability in jQuery

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.


We have discovered 7,099,257 live websites that are affected by CVE-2020-11023.

Run a Free Instant Scan




Affected Software

Product  jQuery
Category JavaScript Frameworks
Vulnerable Domains7,099,257 live websites (42% of jQuery install base)
Vulnerable Versions
  • from 1.0.3 through 3.5
Vulnerable Versions Count269 versions ( 86% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Apr 29, 2020
  • Updated - Oct 21, 2025

Website Distribution by Country

Number of websites using CVE-2020-11023
United States2,165,231 websites



Germany529,414 websites
Russia462,708 websites
Japan449,488 websites
China310,793 websites
France289,979 websites
Israel282,786 websites
GB216,007 websites
Netherlands180,138 websites
Italy179,354 websites

Website Distribution by TLD

Number of websites using CVE-2020-11023
.com3,171,206 websites
.ru375,179 websites
.de340,314 websites
.org256,638 websites
.net231,388 websites
.co.uk162,358 websites
.nl147,138 websites
.it129,757 websites
.jp128,480 websites
.fr109,424 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-11023

Top websites that are affected by CVE-2020-11023. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.***********.com United States**
********.****.br Brazil**
*********.com United States***
*******.com Singapore***
*********.com United States***
***********.com Ireland***
******.com United States***
******.ru Russia***
*******.*********.com United States***
*****************.com United States***
See full domain list

FAQ

CVE-2020-11023 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jQuery
A total of 7,099,257 websites have been identified as vulnerable to CVE-2020-11023, based on global website indexing conducted by WebTechSurvey.
The jQuery is affected by the CVE-2020-11023 vulnerability.
jQuery versions up to 3.5 are vulnerable to CVE-2020-11023.
CVE-2020-11023 is resolved in version 3.5 of jQuery.

References