CVE-2020-11023 is a cross-site scripting vulnerability in jQuery versions 1.0.3 through 3.4.x. When an application passes HTML containing <option> elements from an untrusted source to jQuery DOM-manipulation methods, including .html() and .append(), jQuery may execute untrusted code. The issue can persist even when the HTML was sanitized before it is supplied to the affected methods.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This repository is a proof-of-concept (POC) environment for demonstrating CVE-2020-11023, a cross-site scripting (XSS) vulnerability in jQuery 3.4.1. The repository contains a Dockerfile and docker-compose.yml for easy setup of a vulnerable PHP web application. The main application (src/index.php) accepts user input via POST and directly injects it into the DOM using jQuery's .html() method, which is vulnerable to XSS. The README provides example payloads and mitigation strategies. The application is intended for educational and testing purposes only, and should not be used in production. The main exploit capability is browser-based XSS via injection of arbitrary JavaScript. The main endpoints are the local web server (http://localhost:8080) and the externally loaded jQuery library.
This repository is a proof-of-concept exploit for CVE-2020-11022 and CVE-2020-11023, which are cross-site scripting (XSS) vulnerabilities in jQuery versions prior to 3.5.0. The repository contains two files: a README.md with detailed exploitation instructions and an index.php file that serves as a vulnerable web application. The exploit demonstrates how an attacker can inject arbitrary JavaScript via the 'value' URL parameter, leading to XSS and cookie theft. The attack is performed by hosting index.php on a PHP webserver with a vulnerable jQuery version, then visiting a crafted URL and triggering DOM manipulation via a button. The exploit also shows how to exfiltrate cookies to an attacker-controlled server. The repository is structured as a simple, educational POC and does not include weaponized or automated exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
70 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A jQuery DOM-manipulation vulnerability that can permit untrusted code execution when attacker-controlled HTML containing an <option> tag is passed to affected DOM manipulation methods.
A jQuery vulnerability in which HTML containing an <option> element, when supplied to DOM-manipulation methods, can result in execution of untrusted code. The referenced Rocky Linux 8 advisory identifies installed affected packages and directs administrators to update them.
A jQuery vulnerability in which untrusted HTML containing an <option> tag, when passed to DOM-manipulation methods, can result in untrusted code execution. The notice identifies affected jQuery packages installed on a Rocky Linux 9 host and directs updating them under CIQ advisory crlsa-2025_1329.
A moderate-severity vulnerability tracked as CVE-2020-11023, detected through an AlmaLinux local security check. The supplied CVSS v3 vector indicates network reachability, no privileges required, required user interaction, and low confidentiality and integrity impact with changed scope.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.