jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
We have discovered 1,184,778 live websites that are affected by CVE-2021-41184.
| Product | |
| Category | JavaScript Libraries |
| Vulnerable Domains | 1,184,778 live websites (27% of jQuery UI install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 75 versions ( 78% of all versions) |
| 330,657 websites | |
| 104,932 websites | |
| 71,288 websites | |
| 66,710 websites | |
| 52,460 websites | |
| 46,672 websites | |
| 38,885 websites | |
| 33,000 websites | |
| 30,971 websites | |
| 29,171 websites |
| .com | 459,421 websites |
| .de | 62,136 websites |
| .ru | 54,715 websites |
| .org | 44,846 websites |
| .it | 36,747 websites |
| .net | 32,388 websites |
| .fr | 29,272 websites |
| .co.uk | 28,675 websites |
| .nl | 28,588 websites |
| .cz | 24,911 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.****.br | ** | ||
| ***********.com | *** | ||
| ******.com | *** | ||
| *************.com | *** | ||
| **.com | *** | ||
| ********.com | *** | ||
| ****.*********.com | *** | ||
| *****.**.uk | *,*** | ||
| ***.*********.com | *,*** | ||
| *********************.de | *,*** |
FAQ