jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| jqueryui | jquery_ui | 1.13.0 | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
46
Affected Products
36
References
jqueryui / jquery_ui
| - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - | - |
| netapp | h300s_firmware | - | - |
| netapp | h500s_firmware | - | - |
| netapp | h700s_firmware | - | - |
| netapp | h300e_firmware | - | - |
| netapp | h500e_firmware | - | - |
| netapp | h700e_firmware | - | - |
| netapp | h410s_firmware | - | - |
| netapp | h410c_firmware | - | - |
| debian | debian_linux | - | - |
| drupal | drupal | 7.0 - 7.86 | - |
| drupal | drupal | 9.2.0 - 9.2.11 | - |
| drupal | drupal | 9.3.0 - 9.3.3 | - |
| oracle | agile_plm | - | - |
| oracle | application_express | 22.1.1 | - |
| oracle | banking_platform | - | - |
| oracle | banking_platform | - | - |
| oracle | big_data_spatial_and_graph | 23.1 | - |
| oracle | big_data_spatial_and_graph | - | - |
| oracle | communications_interactive_session_recorder | - | - |
| oracle | communications_operations_monitor | - | - |
| oracle | communications_operations_monitor | - | - |
| oracle | communications_operations_monitor | - | - |
| oracle | hospitality_inventory_management | - | - |
| oracle | hospitality_suite8 | 8.11.0 - 11.14.0 | - |
| oracle | hospitality_suite8 | - | - |
| oracle | jd_edwards_enterpriseone_tools | 9.2.6.3 | - |
| oracle | mysql_enterprise_monitor | 8.0.29 | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | policy_automation | 12.2.0 - 12.2.5 | - |
| oracle | primavera_gateway | 17.7 - 17.12 | - |
| oracle | primavera_gateway | - | - |
| oracle | primavera_gateway | - | - |
| oracle | primavera_gateway | - | - |
| oracle | primavera_gateway | - | - |
| oracle | rest_data_services | 22.1.1 | - |
| oracle | rest_data_services | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
| oracle | weblogic_server | - | - |
| tenable | tenable.sc | 5.21.0 | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability
Impact