CVE-2021-41184

XSS in the `of` option of the `.position()` util

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.


We have discovered 1,184,778 live websites that are affected by CVE-2021-41184.

Run a Free Instant Scan




Affected Software

Product  jQuery UI
Category JavaScript Libraries
Vulnerable Domains1,184,778 live websites (27% of jQuery UI install base)
Vulnerable Versions
  • from 0 through 1.13
Vulnerable Versions Count75 versions ( 78% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 26, 2021
  • Updated - Nov 4, 2025

Website Distribution by Country

Number of websites using CVE-2021-41184
United States330,657 websites



Germany104,932 websites
France71,288 websites
Russia66,710 websites
Italy52,460 websites
GB46,672 websites
Japan38,885 websites
Netherlands33,000 websites
Poland30,971 websites
Czech Republic29,171 websites

Website Distribution by TLD

Number of websites using CVE-2021-41184
.com459,421 websites
.de62,136 websites
.ru54,715 websites
.org44,846 websites
.it36,747 websites
.net32,388 websites
.fr29,272 websites
.co.uk28,675 websites
.nl28,588 websites
.cz24,911 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-41184

Top websites that are affected by CVE-2021-41184. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.****.br Brazil**
***********.com Ireland***
******.com United States***
*************.com United States***
**.com Singapore***
********.com United States***
****.*********.com United States***
*****.**.uk GB*,***
***.*********.com Singapore*,***
*********************.de Germany*,***
See full domain list

FAQ

CVE-2021-41184 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jQuery UI
A total of 1,184,778 websites have been identified as vulnerable to CVE-2021-41184, based on global website indexing conducted by WebTechSurvey.
The jQuery UI is affected by the CVE-2021-41184 vulnerability.
jQuery UI versions up to 1.13 are vulnerable to CVE-2021-41184.
CVE-2021-41184 is resolved in version 1.13 of jQuery UI.

References