CVE-2018-18405: jQuery

Medium severity, CVSS 6.1. EPSS: 1.7% chance of exploitation in the next 30 days.

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

Affected products

  • jQuery jQuery: version 2.2.2 only

Published 2020-04-22. Last modified 2026-06-17.