WPIntell

Source evidence

jQuery Validation Vulnerabilities

White Label CMS · support · 2026-05-07T10:07:00+00:00

complaintsentiment
highseverity
0.82relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 31 rows with source links

16.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
asaini resolved
In your module White Label CMS is using jQuery Validation Plugin version 1.17.0 which is affected by several security vulnerabilities, primarily related to Regular Expression Denial of Service (ReDoS) and Cross-site Scripting (XSS) . [ 1 , 2 ] To secure your application, it is recommended to update to version 1.22.1 or later. [ 1 ] High Severity Vulnerabilities ReDoS (CVE-2021-21252 & CVE-2022-31147): This version contains regular expressions used for URL and email validation that are susceptible to catastrophic backtracking. An attacker can provide a specially crafted input that causes the server or client’s CPU usage to spike, effectively freezing the application (Denial of Service). Fixed in: Version 1.19.5. XSS (CVE-2024-52301 / CVE-2025-3573): Vulnerabilities exist in the showLabel() function and how the plugin handles user-controlled placeholders in localized dictionaries. An attacker could execute arbitrary JavaScript by injecting malicious payloads into these input fields, potentially stealing user data or sessions. Recommendation If are currently using version 1.17.0, you should upgrade the jQuery Validation Library immediately. Version 1.17.0 has been flagged as having at least one high-severity vulnerability by the NVD and NuGet . [ 1 , 2 , 3 ] Hello @asaini , Thanks for reporting this. We have just released a new version that patches this security issue.

Comments

1 shown
VUM Support – Jhay 2026-05-08T04:32:00+00:00

Hello @asaini , Thanks for reporting this. We have just released a new version that patches this security issue.