<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – jQuery (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/jquery.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/jquery-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – jQuery (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-44521 – elFinder is an open-source file manager for web, written in JavaScript using jQu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44521</guid>
    <pubDate>Wed, 27 May 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44521</strong></p>
  <p>elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through a crafted target file hash. Successful exploitation can lead to unauthorized dat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21821 – The HCL BigFix SCM Reporting site contains an outdated and unsupported version o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21821</guid>
    <pubDate>Wed, 13 May 2026 21:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21821</strong></p>
  <p>The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk of client-side attacks such as Cross-Site Scripting (XSS) or manipulation through vulnerable third-party components.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1104</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43892 – AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43892</guid>
    <pubDate>Tue, 12 May 2026 18:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43892</strong></p>
  <p>AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed in 2.1.16.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41247 – elFinder is an open-source file manager for web, written in JavaScript using jQu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41247</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41247</strong></p>
  <p>elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that use the ImageMagick CLI backend, this value is incorporated into shell command st…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40568 – FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40568</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40568</strong></p>
  <p>FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature. The sanitization function `Helper::stripDangerousTags()` (`app/Misc/Helper.php:568`) uses an incomplete blocklist of only four HTML tags (`script`, `form`, `iframe`, `object`) and does not remove event handler attributes.…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32513 – Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32513</guid>
    <pubDate>Wed, 25 Mar 2026 17:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32513</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32121 – OpenEMR is a free and open source electronic health records and medical practice...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32121</guid>
    <pubDate>Wed, 11 Mar 2026 21:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32121</strong></p>
  <p>OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1,  Stored XSS in prescription CSS/HTML print view via patient demographics. That finding involves server-side rendering of patient names via raw PHP echo. This finding involves client-side DOM-based rendering via jQuery .html() in a completely different component (portal/sign/a…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53892 – Blackcat CMS 1.4 contains a remote code execution vulnerability that allows auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53892</guid>
    <pubDate>Mon, 15 Dec 2025 21:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53892</strong></p>
  <p>Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers can upload a zip file with a PHP shell script and execute arbitrary system commands by accessing the uploaded plugin's PHP file with a 'code' parameter.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54726 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54726</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54726</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects JS Archive List: from n/a through < 6.1.6.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-10138 – The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-10138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-10138</guid>
    <pubDate>Sat, 19 Jul 2025 12:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-10138</strong></p>
  <p>The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-10138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34100 – An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34100</guid>
    <pubDate>Thu, 10 Jul 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34100</strong></p>
  <p>An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php file and subsequently execute arbitrary PHP code on the server under the context…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46514 – Cross-Site Request Forgery (CSRF) vulnerability in milat Milat jQuery Automatic ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46514</guid>
    <pubDate>Thu, 24 Apr 2025 16:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46514</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in milat Milat jQuery Automatic Popup milat-jquery-automatic-popup allows Stored XSS.This issue affects Milat jQuery Automatic Popup: from n/a through <= 1.3.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-43958 – An arbitrary file upload vulnerability in the component /jquery-file-upload/serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43958</guid>
    <pubDate>Tue, 22 Apr 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-43958</strong></p>
  <p>An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-26954 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26954</guid>
    <pubDate>Tue, 15 Apr 2025 12:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-26954</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 1pluginjquery ZooEffect 1-jquery-photo-gallery-slideshow-flash allows Reflected XSS.This issue affects ZooEffect: from n/a through <= 1.11.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30560 – Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah jQuery Dropdown Me...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30560</guid>
    <pubDate>Mon, 24 Mar 2025 14:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30560</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah jQuery Dropdown Menu jquery-drop-down-menu-plugin allows Stored XSS.This issue affects jQuery Dropdown Menu: from n/a through <= 3.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-28861 – Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datep...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-28861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-28861</guid>
    <pubDate>Tue, 11 Mar 2025 21:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-28861</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker wpjqp-datepicker allows Stored XSS.This issue affects WP jQuery Persian Datepicker: from n/a through <= 0.1.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-28861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52583 – The WesHacks GitHub repository provides the official Hackathon competition websi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52583</guid>
    <pubDate>Mon, 18 Nov 2024 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52583</strong></p>
  <p>The WesHacks GitHub repository provides the official Hackathon competition website source code for the Muweilah Wesgreen Hackathon. The page `schedule.html` before 17 November 2024 or commit 93dfb83 contains links to `Leostop`, a site that hosts a malicious injected JavaScript file that occurs when bootstrap is run as well as jquery. `Leostop` may be a tracking malware and creates 2 JavaScript fi…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30875 – Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30875</guid>
    <pubDate>Thu, 17 Oct 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30875</strong></p>
  <p>Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. NOTE: this is disputed by the Supplier because it cannot be reproduced, and because the exploitation example does not indicate whether, or how, the example website is using jQ…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-8940 – Vulnerability in the Scriptcase application version 9.4.019, which involves the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8940</guid>
    <pubDate>Wed, 25 Sep 2024 01:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-8940</strong></p>
  <p>Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32753 – Under certain circumstances the camera may be susceptible to known vulnerabiliti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32753</guid>
    <pubDate>Thu, 11 Jul 2024 16:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32753</strong></p>
  <p>Under certain circumstances the camera may be susceptible to known vulnerabilities associated with the JQuery versions prior to 3.5.0 third-party component</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26629 – A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hosp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26629</guid>
    <pubDate>Wed, 10 Jan 2024 09:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26629</strong></p>
  <p>A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5464 – The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5464</guid>
    <pubDate>Tue, 31 Oct 2023 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5464</strong></p>
  <p>The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5430 – The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5430</guid>
    <pubDate>Tue, 31 Oct 2023 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5430</strong></p>
  <p>The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into alre…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31147 – The jQuery Validation Plugin (jquery-validation) provides drop-in validation for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31147</guid>
    <pubDate>Thu, 14 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31147</strong></p>
  <p>The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to supply arbitrary input to the url2 method. This is due to an incomplete fix for CVE-2021-43306. Users should upgrade to version 1.19.5 to receive a patch.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-25495 – The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25495</guid>
    <pubDate>Tue, 15 Mar 2022 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-25495</strong></p>
  <p>The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41132 – OMERO.web provides a web based client and plugin infrastructure. In versions pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41132</guid>
    <pubDate>Thu, 14 Oct 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41132</strong></p>
  <p>OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site scripting possibilities with specially crafted input to a variety of fields. This issue is patched in version 5.11.0. There a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-32682 – elFinder is an open-source file manager for web, written in JavaScript using jQu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32682</guid>
    <pubDate>Mon, 14 Jun 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-32682</strong></p>
  <p>elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed w…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20086 – Improperly Controlled Modification of Object Prototype Attributes ('Prototype Po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20086</guid>
    <pubDate>Fri, 23 Apr 2021 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20086</strong></p>
  <p>Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20083 – Improperly Controlled Modification of Object Prototype Attributes ('Prototype Po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20083</guid>
    <pubDate>Fri, 23 Apr 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20083</strong></p>
  <p>Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20087 – Improperly Controlled Modification of Object Prototype Attributes ('Prototype Po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20087</guid>
    <pubDate>Fri, 23 Apr 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20087</strong></p>
  <p>Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20084 – Improperly Controlled Modification of Object Prototype Attributes ('Prototype Po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20084</guid>
    <pubDate>Fri, 23 Apr 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20084</strong></p>
  <p>Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15154 – baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15154</guid>
    <pubDate>Fri, 28 Aug 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15154</strong></p>
  <p>baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php, index_list_tree.php, jquery.bcTree.js. The issue is fixed in version 4.3.7.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-6978 – In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6978</guid>
    <pubDate>Tue, 24 Mar 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-6978</strong></p>
  <p>In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-477</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-8739 – Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8739</guid>
    <pubDate>Sat, 08 Feb 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-8739</strong></p>
  <p>Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8121 – An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8121</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8121</strong></p>
  <p>An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-9479 – The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-9479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-9479</guid>
    <pubDate>Thu, 10 Oct 2019 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-9479</strong></p>
  <p>The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-9479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-9951 – Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9951</guid>
    <pubDate>Wed, 24 Apr 2019 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-9951</strong></p>
  <p>Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on t…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-9207 – Arbitrary file upload in jQuery Upload File &lt;= 4.0.2</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9207</guid>
    <pubDate>Mon, 19 Nov 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-9207</strong></p>
  <p>Arbitrary file upload in jQuery Upload File <= 4.0.2</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-9208 – Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut &lt;= v1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9208</guid>
    <pubDate>Mon, 05 Nov 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-9208</strong></p>
  <p>Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-9206 – Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Uploa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9206</guid>
    <pubDate>Thu, 11 Oct 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-9206</strong></p>
  <p>Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16045 – `jquery.js` was a malicious module published with the intent to hijack environme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16045</guid>
    <pubDate>Mon, 04 Jun 2018 19:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16045</strong></p>
  <p>`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-506</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-8768 – In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-8768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-8768</guid>
    <pubDate>Sun, 18 Mar 2018 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-8768</strong></p>
  <p>In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10707 – jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a log...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10707</guid>
    <pubDate>Thu, 18 Jan 2018 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10707</strong></p>
  <p>jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-17560 – An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17560</guid>
    <pubDate>Tue, 12 Dec 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-17560</strong></p>
  <p>An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4634 – SQL injection vulnerability in the jQuery autocomplete for indexed_search (rzaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4634</guid>
    <pubDate>Thu, 20 Jun 2013 23:55:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4634</strong></p>
  <p>SQL injection vulnerability in the jQuery autocomplete for indexed_search (rzautocomplete) extension before 0.0.9 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4634">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
