Vulnerability record · CVE-2020-11022 · published 29 April 2020
CVE-2020-11022: jQuery DOM manipulation methods allow XSS even after sanitization
Jquery · Jquery
jQuery versions 1.12.0 through 3.4.x execute untrusted code when HTML from untrusted sources is passed to DOM manipulation methods such as .html() and .append(), even if that HTML was previously sanitized. The flaw is a cross-site scripting issue patched in jQuery 3.5.0, and it matters because sanitization routines that defenders rely on do not prevent execution in affected versions.
Description
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is a widely deployed library XSS with a very high EPSS score, though it requires user interaction and is not in KEV.
What it is
jQuery versions 1.12.0 through 3.4.x execute untrusted code when HTML from untrusted sources is passed to DOM manipulation methods such as .html() and .append(), even if that HTML was previously sanitized. The flaw is a cross-site scripting issue patched in jQuery 3.5.0, and it matters because sanitization routines that defenders rely on do not prevent execution in affected versions.
Impact
An attacker can execute arbitrary script in the context of a victim's browser session, enabling session theft, credential capture, or actions as the victim. The CVSS vector shows scope change with low confidentiality and integrity impact and no availability impact.
Attack surface
Reached over the network through web pages or applications that pass untrusted HTML into jQuery DOM manipulation methods; no authentication is required, but user interaction is required per the CVSS vector (UI:R).
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.99215 probability, 0.99934 percentile), indicating substantial observed exploitation likelihood; references include patch and mitigation advisories.
What to do
- Upgrade jQuery to 3.5.0 or later, which patches this issue.
- Update downstream products and packages that bundle jQuery (for example Drupal, Debian, Fedora, Oracle, NetApp, openSUSE) to versions containing the fix.
- Audit application code for use of .html(), .append() and similar DOM manipulation methods with untrusted or user-supplied HTML.
- Apply the mitigation guidance in the jQuery security advisory GHSA-gxr4-xjj5-5px2 where immediate upgrade is not possible.
- Do not rely on HTML sanitizers alone to prevent this issue on affected jQuery versions.
Detection
- Search source code and bundled libraries for jQuery versions between 1.12.0 and 3.4.x.
- Monitor web application logs and client-side telemetry for script injection attempts targeting DOM manipulation sinks.
- Review dependency manifests and SBOMs for jQuery and for downstream products listed as affected.
- Check for unexpected script execution or DOM changes on pages that render user-supplied HTML.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
70 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-11022 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11022), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.