CVE-2021-41184

XSS in the `of` option of the `.position()` util

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.


We have discovered 1,316,309 live websites that are affected by CVE-2021-41184.

Run a Free Instant Scan




Affected Software

Product  jQuery UI
Category JavaScript Libraries
Vulnerable Domains1,316,309 live websites (28% of jQuery UI install base)
Vulnerable Versions
  • from 0 through 1.13
Vulnerable Versions Count66 versions ( 84% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 26, 2021
  • Updated - Nov 4, 2025

Website Distribution by Country

Number of websites using CVE-2021-41184
United States357,584 websites



Germany116,248 websites
France81,675 websites
Russia73,336 websites
Italy57,534 websites
GB50,250 websites
Japan49,628 websites
Netherlands36,617 websites
Poland33,642 websites
Czech Republic31,953 websites

Website Distribution by TLD

Number of websites using CVE-2021-41184
.com509,043 websites
.de68,093 websites
.ru60,117 websites
.org49,020 websites
.it40,185 websites
.net36,348 websites
.fr32,347 websites
.nl31,561 websites
.co.uk31,158 websites
.cz27,108 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-41184

Top websites that are affected by CVE-2021-41184. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.****.br Brazil**
***********.com Ireland***
******.com United States***
*************.com United States***
**.com Singapore***
****.*********.com United States***
*****.**.uk GB*,***
***.*********.com Singapore*,***
**********.org United States*,***
*********************.de Germany*,***
See full domain list

FAQ

CVE-2021-41184 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jQuery UI
A total of 1,316,309 websites have been identified as vulnerable to CVE-2021-41184, based on global website indexing conducted by WebTechSurvey.
The jQuery UI is affected by the CVE-2021-41184 vulnerability.
jQuery UI versions up to 1.13 are vulnerable to CVE-2021-41184.
CVE-2021-41184 is resolved in version 1.13 of jQuery UI.

References