Vulnerability record · CVE-2020-11023 · published 29 April 2020
CVE-2020-11023: jQuery DOM manipulation methods XSS via untrusted HTML option elements
Jquery · Jquery
jQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM manipulation methods such as .html() and .append(), even after sanitization. The flaw is a cross-site scripting issue patched in jQuery 3.5.0, and it affects a widely embedded library across many downstream products.
Description
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityIt is in CISA KEV with a very high EPSS score and affects a ubiquitous library, though exploitation requires user interaction and yields limited direct impact.
What it is
jQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM manipulation methods such as .html() and .append(), even after sanitization. The flaw is a cross-site scripting issue patched in jQuery 3.5.0, and it affects a widely embedded library across many downstream products.
Impact
An attacker can execute script in the context of a victim's browser session, enabling data theft, session abuse or page manipulation. The CVSS vector shows scope change with low confidentiality and integrity impact.
Attack surface
Reached over the network when an application passes attacker-influenced HTML to a vulnerable jQuery DOM method; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N).
Exploitation
CISA added it to KEV on 2025-01-23 with a remediation due date of 2025-02-13, and EPSS shows a 30-day probability of 0.84887 (99.7th percentile). A public exploit reference exists (packetstormsecurity), though no ransomware campaign use is documented.
What to do
- Upgrade jQuery to 3.5.0 or later wherever the library is bundled or vendored.
- Inventory applications and embedded components using jQuery versions below 3.5.0, including third-party and OEM products.
- Apply vendor-supplied patches for downstream products (Drupal, Oracle, NetApp, Debian, Fedora and others listed).
- Avoid passing untrusted HTML to jQuery DOM manipulation methods; use safe DOM APIs or strict sanitization that accounts for this bypass.
- If patching is not possible, follow CISA guidance to apply vendor mitigations or discontinue use of the affected product.
Detection
- Search code repositories and deployed web roots for jQuery versions below 3.5.0.
- Monitor web application logs for requests delivering HTML containing option elements to endpoints that render user input.
- Use browser or WAF telemetry to detect script execution originating from jQuery DOM manipulation paths.
- Review client-side error and CSP violation reports for inline script activity on pages using vulnerable jQuery.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-11023 to the Known Exploited Vulnerabilities catalog on 23 January 2025 as "JQuery Cross-Site Scripting (XSS) Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 February 2025.
Affected products
52 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-11023 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11023), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.