- Affected version
- 1.5.21
XF 1.5.21 (and some older versions) use jQuery 1.11.0 which has a known XSS security vulnerability of medium severity. https://snyk.io/vuln/npm:jquery:20150627
In the default software, we don't perform cross-domain AJAX requests, and in any case all AJAX requests performed through our built in wrapper always set the dataType.Affected versions of the package are vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain ajax request is performed without the dataType option causing text/javascript responses to be executed.
We use essential cookies to make this site work, and optional cookies to enhance your experience.