jQuery Validation is a lightweight client-side form-validation plugin with a narrow product scope but a substantial embedded footprint across web applications. Its vulnerability profile centers on the jQuery Validation library itself, with durable signal in performance-oriented weakness classes such as inefficient regular expression complexity and uncontrolled resource consumption that arise from input-processing logic. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jqueryvalidation over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21252HIGH The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 con | Jan 13, 2021 | 7.5 | 26 | NO | NO |
CVE-2022-31147HIGH The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of | Jul 14, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-43306HIGH An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 me | Jun 2, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jqueryvalidation.
Media articles that mention a CVE ID that affects a product developed by Jqueryvalidation — matched by CVE ID, not by vendor name.