jQuery UI is a focused widget and interaction library that, despite a narrow product footprint, is embedded across countless web applications and interfaces. The recurring vulnerability signal centers on cross-site scripting weaknesses arising from improper input neutralization during page generation, a class endemic to client-side UI frameworks that process untrusted content. Defenders tracking this library should inventory downstream applications that depend on it, since remediation requires those applications to rebuild and redeploy rather than patching jQuery UI in isolation; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jqueryui over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41184MEDIUM jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execut | Oct 26, 2021 | 6.1 | 42 | NO | NO |
CVE-2021-41182MEDIUM jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may e | Oct 26, 2021 | 6.1 | 42 | NO | NO |
CVE-2016-7103MEDIUM Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog fu | Mar 15, 2017 | 6.1 | 29 | NO | NO |
CVE-2010-5312MEDIUM Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via t | Nov 24, 2014 | 6.1 | 29 | NO | NO |
CVE-2021-41183MEDIUM jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may | Oct 26, 2021 | 6.1 | 25 | NO | NO |
CVE-2022-31160MEDIUM jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site sc | Jul 20, 2022 | 6.1 | 22 | NO | NO |
CVE-2012-6662MEDIUM Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject ar | Nov 24, 2014 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jqueryui.
Media articles that mention a CVE ID that affects a product developed by Jqueryui — matched by CVE ID, not by vendor name.