CVE-2021-41184
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
More exploitable than 99% of all CVEs · Top 1%
Is your site exposed to this?
Run a free scan. UNPWNED fingerprints your stack and flags this CVE class if the affected technology is detected.
- Published
- 2021-10-26
- Last modified
- 2026-08-25
- Affected
- Drupal
Related exploited CVEs in Drupal
Data from the National Vulnerability Database (NVD), CISA KEV, and FIRST.org EPSS. This product uses the NVD API but is not endorsed or certified by the NVD. EPSS is a probability estimate, not a guarantee of exploitation.
