CVE-2020-7656

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.


We have discovered 2,114,463 live websites that are affected by CVE-2020-7656.

Test my site




Affected Software

Product  jQuery
Category JavaScript Libraries
Vulnerable Domains2,114,463 live websites (10.97% of jQuery install base)
Vulnerable Versions
  • from 0 before 1.9
Vulnerable Versions Count410 versions ( 49.64% of all versions)



Details

  • Published - May 19, 2020
  • Updated - Aug 4, 2024

CVE-2020-7656 usage by Country

United States787,206 websites



Germany192,189 websites
China148,848 websites
Japan135,261 websites
Russia106,200 websites
France84,460 websites
GB52,358 websites
Poland42,974 websites
Hong Kong42,111 websites
Netherlands39,127 websites

CVE-2020-7656 usage by TLD

.com1,005,826 websites
.de129,278 websites
.ru94,462 websites
.org90,144 websites
.net79,803 websites
.co.uk46,690 websites
.jp37,872 websites
.nl36,117 websites
.pl33,811 websites
.cn31,381 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-7656

Top websites that are affected by CVE-2020-7656. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States***
******.ru Russia***
*****************.com United States***
***.****.ru Russia***
**.ru Russia***
************.ru Russia***
**.******.com Canada***
*********.com United States***
************.com United States*,***
****.org United States*,***
See full domain list

FAQ

A total of 2,114,463 websites have been identified as vulnerable to CVE-2020-7656, discovered through global website indexing conducted by WebTechSurvey.
jQuery is susceptible to CVE-2020-7656 vulnerability.
jQuery versions before 1.9 are vulnerable to CVE-2020-7656.
Version 1.9 of jQuery addresses the CVE-2020-7656 security vulnerability.