Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-31160

22
FAUCET Score

CVE-2022-31160 is a cross-site scripting (XSS) vulnerability affecting jQuery UI versions prior to 1.13.2, as well as products like Debian, Drupal, and FedoraProject that incorporate vulnerable jQuery UI versions. The vulnerability arises when a checkboxradio widget is initialized on an input within a label, and encoded HTML entities in the initial HTML are erroneously decoded upon refreshing the widget, potentially leading to JavaScript execution. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction (UI:R) and has low impact on confidentiality and integrity (C:L/I:L). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.13.2CPE matchmatch criteria
cpe:2.3:a:jqueryui:jquery_ui:*:*:*:*:*:jquery:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.48%
Probability of exploitation in next 30 days
EPSS Percentile
82.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0248 is in the 92nd percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.webjars.npm:jquery-uiFixed in: 1.13.2
npmpatch availablevia ghsa
Product: jquery-uiFixed in: 1.13.2
nugetpatch availablevia ghsa
Product: jQuery.UI.CombinedFixed in: 1.13.2
rubygemspatch availablevia ghsa
Product: jquery-ui-railsFixed in: 8.0.0
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: python-XStatic-jquery-ui
redhatno patchvia redhat_api
Product: Red Hat Fuse 7Fixed in: hawtio
redhatno patchvia redhat_api
Product: Red Hat Fuse 7Fixed in: swagger-ui
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: python-XStatic-jquery-ui
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.1Fixed in: python-XStatic-jquery-ui

Vendor Advisories (2)

redhatCVE-2022-31160Important

jqueryui: XSS when refreshing a checkboxradio with an HTML-like initial text label

Jul 20, 2022
npmGHSA-h6gj-6jjq-h8g9medium

jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label

Jul 18, 2022

References

blog.jqueryui.com / 2022/07/jquery-ui-1-13-2-released
Release NotesVendor Advisory
github.com / jquery/jquery-ui/commit/8cc5bae1caa1fcf96bf5862c5646c787020ba3f9
PatchThird Party Advisory
github.com / jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9
ExploitMitigationRelease NotesThird Party Advisory
lists.debian.org / debian-lts-announce/2022/12/msg00015.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6XBR3G3JR5ZIOJDO4224M3INXDS2VFDD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/J5LGNTICB5BRFAG3DHVVELS6H3CZSQMO
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QB2FJQXCNHO32VGVOC6DY6IPGVE4VDU6
security.netapp.com / advisory/ntap-20220909-0007
Third Party Advisory
drupal.org / sa-contrib-2022-052
Third Party Advisory