VYPR
Medium severity6.1NVD Advisory· Published Apr 22, 2020· Updated Jun 17, 2026

CVE-2018-18405

CVE-2018-18405

Description

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • jQuery/jQuery2 versions
    cpe:2.3:a:jquery:jquery:2.2.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:jquery:jquery:2.2.2:*:*:*:*:*:*:*
    • (no CPE)range: = 2.2.2
  • jQuery/jQuerydescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.