CVE-2021-41183
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
More exploitable than 95% of all CVEs · Top 5%
Is your site exposed to this?
Run a free scan. UNPWNED fingerprints your stack and flags this CVE class if the affected technology is detected.
- Published
- 2021-10-26
- Last modified
- 2026-08-25
- Affected
- Drupal, MySQL
Related exploited CVEs in Drupal
Data from the National Vulnerability Database (NVD), CISA KEV, and FIRST.org EPSS. This product uses the NVD API but is not endorsed or certified by the NVD. EPSS is a probability estimate, not a guarantee of exploitation.
