Description
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Events Calendar SQL Injection (1.0)
WebLogic CVE-2016-3505 Vulnerability (CVE-2016-3505)
Oracle JRE CVE-2020-14779 Vulnerability (CVE-2020-14779)
Next.js Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-44574)
Oracle Database Server CVE-2006-5344 Vulnerability (CVE-2006-5344)