jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.
We have discovered 1,617,003 live websites that are affected by CVE-2021-41182.
Product | |
Category | JavaScript Libraries |
Vulnerable Domains | 1,617,003 live websites (32.85% of jQuery UI install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 96 versions ( 82.76% of all versions) |
![]() | 525,871 websites |
![]() | 160,206 websites |
![]() | 111,179 websites |
![]() | 81,521 websites |
![]() | 52,896 websites |
![]() | 52,125 websites |
![]() | 45,007 websites |
![]() | 39,916 websites |
![]() | 39,147 websites |
![]() | 32,799 websites |
.com | 637,849 websites |
.de | 84,288 websites |
.ru | 69,731 websites |
.org | 63,329 websites |
.net | 43,599 websites |
.fr | 41,688 websites |
.nl | 39,385 websites |
.co.uk | 38,866 websites |
.it | 34,147 websites |
.pl | 33,861 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.****.br | ![]() | ** | |
***********.com | ![]() | *** | |
******.com | ![]() | *** | |
*************.com | ![]() | *** | |
**.com | ![]() | *** | |
********.com | ![]() | *** | |
****.*********.com | ![]() | *** | |
*****.**.uk | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
***.*********.com | ![]() | *,*** |
FAQ