January 23, 2025 · Applied Cybernetics Group
CVE-2020-11023 — JQuery JQuery
JQuery Cross-Site Scripting (XSS) Vulnerability
- Added to KEV
2025-01-23- Federal due date
2025-02-13- Vendor
- JQuery
- Product
- JQuery
- EPSS
- 97.1th percentile (score 0.347, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-11023
CISA short description
JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.