VYPR

Maven package

org.webjars.npm/jquery-ui

pkg:maven/org.webjars.npm/jquery-ui

Vulnerabilities (7)

  • CVE-2022-31160Jul 20, 2022
    affected < 1.13.2fixed 1.13.2

    jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent l

  • CVE-2021-41184Oct 26, 2021
    affected < 1.13.0fixed 1.13.0

    jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option

  • CVE-2021-41183Oct 26, 2021
    affected < 1.13.0fixed 1.13.0

    jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text

  • CVE-2021-41182Oct 26, 2021
    affected < 1.13.0fixed 1.13.0

    jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altFi

  • CVE-2016-7103MedMar 15, 2017
    affected < 1.12.0fixed 1.12.0

    Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

  • CVE-2012-6662Nov 24, 2014
    affected < 1.10.0fixed 1.10.0

    Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplet

  • CVE-2010-5312MedNov 24, 2014
    affected >= 1.7.0, < 1.10.0fixed 1.10.0

    Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.