Description
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
Remediation
References
Related Vulnerabilities
XWikiplatform Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2025-66473)
WordPress Plugin Rate my Post-WP Rating System Multiple Vulnerabilities (3.3.4)
WordPress 2.2 Multiple Vulnerabilities (2.2)
Oracle JRE CVE-2018-2637 Vulnerability (CVE-2018-2637)
WordPress Plugin Analyticator Cross-Site Request Forgery (6.4.9.3)