CVE-2021-41182

XSS in the `altField` option of the Datepicker widget

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.


We have discovered 1,132,495 live websites that are affected by CVE-2021-41182.

Run a Free Instant Scan




Affected Software

Product  jQuery UI
Category JavaScript Libraries
Vulnerable Domains1,132,495 live websites (26% of jQuery UI install base)
Vulnerable Versions
  • from 0 through 1.13
Vulnerable Versions Count79 versions ( 77% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 26, 2021
  • Updated - Feb 13, 2025

Website Distribution by Country

Number of websites using CVE-2021-41182
United States316,938 websites



Germany99,954 websites
France67,277 websites
Russia61,819 websites
Italy51,418 websites
Japan44,330 websites
GB43,672 websites
Netherlands31,262 websites
Poland29,602 websites
Czech Republic27,741 websites

Website Distribution by TLD

Number of websites using CVE-2021-41182
.com440,157 websites
.de59,657 websites
.ru50,770 websites
.org42,976 websites
.it36,647 websites
.net31,250 websites
.fr27,946 websites
.nl26,971 websites
.co.uk26,864 websites
.cz23,771 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-41182

Top websites that are affected by CVE-2021-41182. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.****.br Brazil**
*******.com Singapore***
***********.com Ireland***
******.com United States***
*************.com United States***
**.com Singapore***
********.com United States***
****.*********.com United States***
*****.************.com United States*,***
*****.**.uk GB*,***
See full domain list

FAQ

CVE-2021-41182 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jQuery UI
A total of 1,132,495 websites have been identified as vulnerable to CVE-2021-41182, based on global website indexing conducted by WebTechSurvey.
The jQuery UI is affected by the CVE-2021-41182 vulnerability.
jQuery UI versions up to 1.13 are vulnerable to CVE-2021-41182.
CVE-2021-41182 is resolved in version 1.13 of jQuery UI.

References