jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
We have discovered 1,316,309 live websites that are affected by CVE-2021-41184.
| Product | |
| Category | JavaScript Libraries |
| Vulnerable Domains | 1,316,309 live websites (28% of jQuery UI install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 66 versions ( 84% of all versions) |
| 357,584 websites | |
| 116,248 websites | |
| 81,675 websites | |
| 73,336 websites | |
| 57,534 websites | |
| 50,250 websites | |
| 49,628 websites | |
| 36,617 websites | |
| 33,642 websites | |
| 31,953 websites |
| .com | 509,043 websites |
| .de | 68,093 websites |
| .ru | 60,117 websites |
| .org | 49,020 websites |
| .it | 40,185 websites |
| .net | 36,348 websites |
| .fr | 32,347 websites |
| .nl | 31,561 websites |
| .co.uk | 31,158 websites |
| .cz | 27,108 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.****.br | ** | ||
| ***********.com | *** | ||
| ******.com | *** | ||
| *************.com | *** | ||
| **.com | *** | ||
| ****.*********.com | *** | ||
| *****.**.uk | *,*** | ||
| ***.*********.com | *,*** | ||
| **********.org | *,*** | ||
| *********************.de | *,*** |
FAQ