{
  "id": "CVE-2020-11023",
  "url": "https://spydr.io/cve/CVE-2020-11023",
  "published": "2020-04-29T21:15:11.743Z",
  "modified": "2026-06-17T02:48:52.930Z",
  "score": 6.1,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "score_source": "NVD",
  "epss": 0.84887,
  "epss_percentile": 0.99707,
  "exploited": true,
  "kev": {
    "added": "2025-01-23",
    "due": "2025-02-13",
    "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
    "ransomware": "Unknown",
    "name": "JQuery Cross-Site Scripting (XSS) Vulnerability",
    "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6 ; https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2020-11023"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "jquery"
  ],
  "products": [
    "jQuery"
  ],
  "cwes": [
    "CWE-79"
  ],
  "description": "In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 6.1,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html",
      "tags": [
        "Broken Link",
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/162160/jQuery-1.0.3-Cross-Site-Scripting.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://blog.jquery.com/2020/04/10/jquery-3-5-0-released",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://jquery.com/upgrade-guide/3.5/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36%40%3Cissues.flink.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb%40%3Cissues.hive.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6%40%3Cdev.felix.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec%40%3Cissues.hive.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c%40%3Cgitbox.hive.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330%40%3Cdev.felix.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef%40%3Cdev.felix.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48%40%3Cissues.flink.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5%40%3Cissues.hive.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16%40%3Cdev.felix.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae%40%3Cissues.flink.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494%40%3Cdev.felix.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760%40%3Cissues.flink.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1%40%3Cissues.hive.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49%40%3Cissues.hive.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d%40%3Cissues.flink.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c%40%3Cissues.flink.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c%40%3Ccommits.felix.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11023",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
