Found on a DOM-XSS scan: Results from scanning URL:
-https://code.jquery.com/jquery-1.11.2.min.js
Number of sources found: 43
Number of sinks found: 19
Mitigated through Decentraleyes extension…chrome-extension://ldpochfccmkkmhdbclfhpagapcfdljkj/resources/jquery/1.11.2/jquery.min.jsm?_=920a76b773470b239f10c261
Medium risk threat: https://retire.insecurity.today/#!/scan/ad88518ae1feecd035f9a64f255e3818222c108e6bf2749a905271c9a72dfd46
/jquery-1.11.2.js
issue 2432
issue 11974
issue 4642
issue 4647
Bug 9521 - $(“#”)
Bug 11290 - $(“element[attribute=‘’”)
jQuery issue 2432 - 3rd party $.get() auto executes if content type is text/javascript
jQuery issue 11974 - parseHTML executes inline scripts like event handlers
jQuery issue 4642 - htmlPrefilter unwraps things it shouldn’t
jQuery issue 4647 - select/option wrapping unwraps can cause XSS
polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)