<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:37:20 +0000</lastBuildDate>
    <item>
      <title>BIT-drupal-2021-41183 — XSS in `*Text` options of the Datepicker widget</title>
      <link>https://cve.radiocsirt.org/vuln/bit-drupal-2021-41183</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: drupal&lt;/p&gt;
&lt;p&gt;jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: drupal&lt;/p&gt;
&lt;p&gt;jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-drupal-2021-41183</guid>
    </item>
    <item>
      <title>certfr-2022-avi-058 — De multiples vulnérabilités ont été découvertes dans Drupal core. Elles
permettent à un attaquant de provoquer une inje…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-058</link>
      <description>certfr-2022-avi-058</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-058</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-ND69835 — jQuery-UI is the official jQuery user interface library</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-nd69835</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: drupal7&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the drupal7 package. jQuery-UI is the official jQuery user interface library.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: drupal7&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the drupal7 package. jQuery-UI is the official jQuery user interface library.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-nd69835</guid>
    </item>
    <item>
      <title>EUVD-2026-215980</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215980</link>
      <description>EUVD-2026-215980</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215980</guid>
    </item>
    <item>
      <title>fkie_cve-2021-41183</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41183</link>
      <description>&lt;p&gt;jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-41183</guid>
    </item>
    <item>
      <title>GHSA-j7qv-pgf6-hvh4 — XSS in `*Text` options of the Datepicker widget in jquery-ui</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j7qv-pgf6-hvh4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jquery-ui, Maven: org.webjars.npm:jquery-ui, RubyGems: jquery-ui-rails, NuGet: jQuery.UI.Combined&lt;/p&gt;
&lt;p&gt;### Impact
Accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the following way:
```js
$( &amp;#34;#datepicker&amp;#34; ).datepicker( {
	showButtonPanel: true,
	showOn: &amp;#34;both&amp;#34;,
	closeText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;closeText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	currentText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;currentText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	prevText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;prevText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	nextText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;nextText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	buttonText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;buttonText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	appendText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;appendText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
} );
```
will call `doEvilThing` with 6 different parameters coming from all `*Text` options.&lt;/p&gt;
&lt;p&gt;### Patches
The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML.&lt;/p&gt;
&lt;p&gt;### Workarounds
A workaround is to not accept the value of the `*Text` options from untrusted sources.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery UI repo](https://github.com/jquery/jquery-ui/issues). If you don&amp;#39;t find an answer, open a new issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jquery-ui, Maven: org.webjars.npm:jquery-ui, RubyGems: jquery-ui-rails, NuGet: jQuery.UI.Combined&lt;/p&gt;
&lt;p&gt;### Impact
Accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the following way:
```js
$( &amp;#34;#datepicker&amp;#34; ).datepicker( {
	showButtonPanel: true,
	showOn: &amp;#34;both&amp;#34;,
	closeText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;closeText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	currentText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;currentText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	prevText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;prevText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	nextText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;nextText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	buttonText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;buttonText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
	appendText: &amp;#34;&amp;lt;script&amp;gt;doEvilThing( &amp;#39;appendText XSS&amp;#39; )&amp;lt;/script&amp;gt;&amp;#34;,
} );
```
will call `doEvilThing` with 6 different parameters coming from all `*Text` options.&lt;/p&gt;
&lt;p&gt;### Patches
The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML.&lt;/p&gt;
&lt;p&gt;### Workarounds
A workaround is to not accept the value of the `*Text` options from untrusted sources.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery UI repo](https://github.com/jquery/jquery-ui/issues). If you don&amp;#39;t find an answer, open a new issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j7qv-pgf6-hvh4</guid>
    </item>
    <item>
      <title>gsd-2021-41183</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-41183</link>
      <description>gsd-2021-41183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-41183</guid>
    </item>
    <item>
      <title>OESA-2022-1693 — python-XStatic-jquery-ui security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1693</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP3: python-XStatic-jquery-ui&lt;/p&gt;
&lt;p&gt;jquery-ui javascript library packaged for setuptools (easy_install) / pip. This package is intended to be used by **any** project that needs these files. It intentionally does **not** provide any extra code except some metadata **nor** has any extra requirements. You MAY use some minimal support code from the XStatic base package, if you like. You can find more info about the xstatic packaging way in the package `XStatic`.&#13;
&#13;
Security Fix(es):&#13;
&#13;
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.(CVE-2021-41183)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP3: python-XStatic-jquery-ui&lt;/p&gt;
&lt;p&gt;jquery-ui javascript library packaged for setuptools (easy_install) / pip. This package is intended to be used by **any** project that needs these files. It intentionally does **not** provide any extra code except some metadata **nor** has any extra requirements. You MAY use some minimal support code from the XStatic base package, if you like. You can find more info about the xstatic packaging way in the package `XStatic`.&#13;
&#13;
Security Fix(es):&#13;
&#13;
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.(CVE-2021-41183)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1693</guid>
    </item>
    <item>
      <title>RHSA-2022:4711 — Red Hat Security Advisory: RHV Manager (ovirt-engine) [ovirt-4.5.0] security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:4711</link>
      <description>&lt;p&gt;nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-trim-off-newlines: ReDoS via string processing nodejs-normalize-url: ReDoS for data URLs jquery-ui: XSS in the altField option of the datepicker widget jquery-ui: XSS in *Text options of the datepicker widget jquery-ui: XSS in the &amp;#39;of&amp;#39; option of the .position() util&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-trim-off-newlines: ReDoS via string processing nodejs-normalize-url: ReDoS for data URLs jquery-ui: XSS in the altField option of the datepicker widget jquery-ui: XSS in *Text options of the datepicker widget jquery-ui: XSS in the &amp;#39;of&amp;#39; option of the .position() util&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:4711</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-41183</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41183</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jqueryui, Ubuntu:Pro:16.04:LTS: jqueryui, Ubuntu:Pro:18.04:LTS: jqueryui, Ubuntu:20.04:LTS: jqueryui&lt;/p&gt;
&lt;p&gt;jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jqueryui, Ubuntu:Pro:16.04:LTS: jqueryui, Ubuntu:Pro:18.04:LTS: jqueryui, Ubuntu:20.04:LTS: jqueryui&lt;/p&gt;
&lt;p&gt;jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41183</guid>
    </item>
    <item>
      <title>VDE-2022-019 — Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-019</link>
      <description>&lt;p&gt;For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-019</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1729 — jQuery: Mehrere Schwachstellen ermöglichen Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1729</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jQuery ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jQuery ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1729</guid>
    </item>
  </channel>
</rss>
