jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
We have discovered 2,114,463 live websites that are affected by CVE-2020-7656.
Product | |
Category | JavaScript Libraries |
Vulnerable Domains | 2,114,463 live websites (10.97% of jQuery install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 410 versions ( 49.64% of all versions) |
![]() | 787,206 websites |
![]() | 192,189 websites |
![]() | 148,848 websites |
![]() | 135,261 websites |
![]() | 106,200 websites |
![]() | 84,460 websites |
![]() | 52,358 websites |
![]() | 42,974 websites |
![]() | 42,111 websites |
![]() | 39,127 websites |
.com | 1,005,826 websites |
.de | 129,278 websites |
.ru | 94,462 websites |
.org | 90,144 websites |
.net | 79,803 websites |
.co.uk | 46,690 websites |
.jp | 37,872 websites |
.nl | 36,117 websites |
.pl | 33,811 websites |
.cn | 31,381 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | *** | |
******.ru | ![]() | *** | |
*****************.com | ![]() | *** | |
***.****.ru | ![]() | *** | |
**.ru | ![]() | *** | |
************.ru | ![]() | *** | |
**.******.com | ![]() | *** | |
*********.com | ![]() | *** | |
************.com | ![]() | *,*** | |
****.org | ![]() | *,*** |
FAQ