jQuery vendor intelligence

jQuery Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting jQuery products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse jQuery KEVs Full KEV feed
Total KEVs
4
Known exploited vulnerabilities affecting jQuery products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
3
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
jQuery KEVs with sensor-observed exploitation activity

The catalog gap matters for jQuery exposure

Three of the four exploited jQuery CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss three-quarters of this vendor portfolio.

25%
Covered by CISA
75%
Beyond CISA
4
Product families

Attested jQuery CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2017-1000170

jqueryFileTree 2.1.5 and older Directory Traversal

jqueryFileTree High Beyond CISA 20 Jun 2025
CVE-2021-20083

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious...

jquery-plugin-query-object High Beyond CISA 11 Mar 2022
CVE-2014-8739

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative...

File Upload Plugin High Beyond CISA 08 Feb 2020
CVE-2020-11023

Potential XSS vulnerability in jQuery

jQuery Confirmed In CISA 23 Jan 2025

Showing 4 of 4 jQuery known exploited vulnerabilities.

Recurring weakness patterns

Improperly controlled modification, limitation, and unrestricted upload account for three mapped occurrences across this jQuery KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.