{
    "id": "CVE-2020-11023",
    "published": "2020-04-29 21:15:11",
    "last_modified": "2026-06-17 02:48:52",
    "cvss_score": "6.9",
    "cvss_severity": "MEDIUM",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N",
    "cwe": "CWE-79",
    "description": "In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.",
    "epss_score": "0.84887",
    "epss_percentile": "0.99706",
    "kev": 1,
    "kev_due": "2025-02-13",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:25:50",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2025-02-13."
    },
    "products": [
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "drupal",
            "product": "drupal"
        },
        {
            "vendor": "fedoraproject",
            "product": "fedora"
        },
        {
            "vendor": "jquery",
            "product": "jquery"
        },
        {
            "vendor": "netapp",
            "product": "h300s"
        },
        {
            "vendor": "netapp",
            "product": "h300s_firmware"
        },
        {
            "vendor": "netapp",
            "product": "h500s"
        },
        {
            "vendor": "netapp",
            "product": "h500s_firmware"
        },
        {
            "vendor": "netapp",
            "product": "h700s"
        },
        {
            "vendor": "netapp",
            "product": "h700s_firmware"
        },
        {
            "vendor": "oracle",
            "product": "application_express"
        },
        {
            "vendor": "oracle",
            "product": "application_testing_suite"
        },
        {
            "vendor": "oracle",
            "product": "banking_enterprise_collections"
        },
        {
            "vendor": "oracle",
            "product": "banking_platform"
        },
        {
            "vendor": "oracle",
            "product": "blockchain_platform"
        },
        {
            "vendor": "oracle",
            "product": "business_intelligence"
        },
        {
            "vendor": "oracle",
            "product": "communications_analytics"
        },
        {
            "vendor": "oracle",
            "product": "communications_eagle_application_processor"
        },
        {
            "vendor": "oracle",
            "product": "communications_element_manager"
        },
        {
            "vendor": "oracle",
            "product": "communications_interactive_session_recorder"
        },
        {
            "vendor": "oracle",
            "product": "communications_operations_monitor"
        },
        {
            "vendor": "oracle",
            "product": "communications_services_gatekeeper"
        },
        {
            "vendor": "oracle",
            "product": "communications_session_report_manager"
        },
        {
            "vendor": "oracle",
            "product": "communications_session_route_manager"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_regulatory_reporting_for_de_nederlandsche_bank"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_revenue_management_and_billing_analytics"
        },
        {
            "vendor": "oracle",
            "product": "health_sciences_inform"
        },
        {
            "vendor": "oracle",
            "product": "healthcare_translational_research"
        },
        {
            "vendor": "oracle",
            "product": "hyperion_financial_reporting"
        },
        {
            "vendor": "oracle",
            "product": "jd_edwards_enterpriseone_orchestrator"
        },
        {
            "vendor": "oracle",
            "product": "jd_edwards_enterpriseone_tools"
        },
        {
            "vendor": "oracle",
            "product": "oss_support_tools"
        },
        {
            "vendor": "oracle",
            "product": "peoplesoft_enterprise_human_capital_management_resources"
        },
        {
            "vendor": "oracle",
            "product": "primavera_gateway"
        },
        {
            "vendor": "oracle",
            "product": "rest_data_services"
        },
        {
            "vendor": "oracle",
            "product": "siebel_mobile"
        },
        {
            "vendor": "oracle",
            "product": "storagetek_acsls"
        },
        {
            "vendor": "oracle",
            "product": "storagetek_tape_analytics_sw_tool"
        },
        {
            "vendor": "oracle",
            "product": "webcenter_sites"
        },
        {
            "vendor": "oracle",
            "product": "weblogic_server"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2020-11023",
        "date_added": "2025-01-23",
        "due_date": "2025-02-13",
        "vendor": "JQuery",
        "product": "JQuery",
        "name": "JQuery Cross-Site Scripting (XSS) Vulnerability",
        "ransomware": 0
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "49767",
            "title": "jQuery 1.0.3 - Cross-Site Scripting (XSS)",
            "date": "2021-04-14",
            "url": "https://www.exploit-db.com/exploits/49767"
        }
    ],
    "refs_list": [
        "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html",
        "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html",
        "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html",
        "http://packetstormsecurity.com/files/162160/jQuery-1.0.3-Cross-Site-Scripting.html",
        "https://blog.jquery.com/2020/04/10/jquery-3-5-0-released",
        "https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6",
        "https://jquery.com/upgrade-guide/3.5/",
        "https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36%40%3Cissues.flink.apache.org%3E",
        "https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb%40%3Cissues.hive.apache.org%3E",
        "https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6%40%3Cdev.felix.apache.org%3E",
        "https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec%40%3Cissues.hive.apache.org%3E",
        "https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c%40%3Cgitbox.hive.apache.org%3E",
        "https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330%40%3Cdev.felix.apache.org%3E",
        "https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef%40%3Cdev.felix.apache.org%3E",
        "https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48%40%3Cissues.flink.apache.org%3E",
        "https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5%40%3Cissues.hive.apache.org%3E",
        "https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16%40%3Cdev.felix.apache.org%3E",
        "https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae%40%3Cissues.flink.apache.org%3E",
        "https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494%40%3Cdev.felix.apache.org%3E",
        "https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760%40%3Cissues.flink.apache.org%3E",
        "https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1%40%3Cissues.hive.apache.org%3E",
        "https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49%40%3Cissues.hive.apache.org%3E",
        "https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d%40%3Cissues.flink.apache.org%3E",
        "https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c%40%3Cissues.flink.apache.org%3E",
        "https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c%40%3Ccommits.felix.apache.org%3E"
    ]
}