Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
Windows Tipps & SecurityOneDrive deleting files automatically in Windows 11(01.10.2026 um 14:36 Uhr)
•••••••
Windows Tipps & SecurityKomprimieren Sie Bilder mit Squoosh und sparen Sie Speicherplatz(02.10.2026 um 08:00 Uhr)
•••
Windows Tipps & SecurityOneDrive deleting files automatically in Windows 11(01.10.2026 um 14:36 Uhr)
•••••••
Windows Tipps & SecurityKomprimieren Sie Bilder mit Squoosh und sparen Sie Speicherplatz(02.10.2026 um 08:00 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

jQuery End of Life: What's Actually EOL (and What Isn't)

Originally published on endoflife.ai. Let's clear up the most-searched question first: jQuery is not end-of-life. jQuery core is still actively maintained — t…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Originally published on endoflife.ai.



Let's clear up the most-searched question first: jQuery is not end-of-life. jQuery core is still actively maintained — the 3.x line gets security releases and 4.x is the modern successor. On the EOL Risk Score, jQuery sits at just 20 (Low).



But that headline hides the real problem. The parts of the jQuery ecosystem most sites depend on are end-of-life: jQuery 1.x and 2.x got no releases since 2016, jQuery UI reached EOL on August 5, 2024, and jQuery Mobile was archived years ago. And the catch the Low score doesn't capture — old jQuery versions carry known, patchable XSS vulnerabilities.






jQuery core versions — what's maintained






































Version Maintenance reality Status Risk Score
jQuery 1.x No releases since 1.12.4 (May 2016) Unmaintained 20
jQuery 2.x No releases since 2.2.4 (May 2016) Unmaintained 20
jQuery 3.x Maintained · latest 3.7.1 Maintained 20
jQuery 4.x Newest line · drops legacy IE Current 20



"No EOL date" ≠ "no updates." jQuery 1.x/2.x have a Low score because jQuery never formally declared them EOL — but the project stopped shipping releases for both in May 2016. In practice they're unmaintained; the only supported path is 3.x or 4.x.







The real risk: old versions, known CVEs



The EOL Risk Score measures lifecycle status. It doesn't track version-specific vulnerabilities — and jQuery has well-known ones fixed in specific releases:





  • CVE-2020-11022 and CVE-2020-11023 — XSS flaws fixed in jQuery 3.5.0 (April 2020). Any jQuery older than 3.5.0 — all of 1.x/2.x and early 3.x — is vulnerable.


  • CVE-2019-11358 — prototype pollution via jQuery.extend, fixed in jQuery 3.4.0.




If you're running jQuery below 3.5.0, you're shipping known XSS to your users. The fix is free: upgrade to current 3.x (3.7.1) or 4.x.




This is the same blind spot covered in the CVE blind spot — lifecycle status and CVE exposure are two different axes, and you have to check both.






jQuery UI & jQuery Mobile — the EOL pieces



Unlike jQuery core, jQuery UI is genuinely end-of-life — dated to August 5, 2024, with a Risk Score of 55 (Elevated). The widget library (datepickers, dialogs, autocomplete) is no longer developed. jQuery Mobile went further — archived and deprecated years ago.



Replacements: modern component libraries or native HTML (<dialog>, <input type="date">) cover most jQuery UI use cases.






How to fix it





  1. Find which jQuery version you actually ship. jQuery.fn.jquery prints the loaded version in the console. Anything below 3.5.0 is a priority.


  2. Add jQuery Migrate. It restores deprecated APIs and logs every deprecation your code hits — a checklist from your real usage. Use it as a temporary bridge.


  3. Upgrade to current jQuery 3.x (3.7.1). Closes the known XSS CVEs; most compatible target.


  4. Replace jQuery UI and jQuery Mobile. Separately EOL — swap for maintained components or native controls.


  5. Consider whether you still need jQuery. Much of what it was indispensable for is now native (querySelectorAll, fetch, classList). The goal is "patched," not necessarily "removed."






Full guide and live data at endoflife.ai. Scan your front-end free with the Stack Scanner.

Cyber Threat Intelligence & Forensik

Bedrohungsgraph · ATT&CK-Mapping · Exploit-Belege
IoC Intelligence
3 Indikatoren · Defanged · STIX 2.1
CVE-2020-11022CVE-2020-11023CVE-2019-11358
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
2 Knoten · 1 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
CVE-2020-11023
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Aktive Angriffe beobachtet (CISA KEV / EPSS)
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
CRITICAL WEAPONIZED · Index 80/100
Exploit-DB
EDB-49767
Interaktion
Interaktion nötig
Authentifizierung
Nicht erforderlich

Compliance, SLA & Vendor Adherence

Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 6.9CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Impact: 4.72 | Exploitability: 1.62
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACH
Hoch (High)
Erfordert Vorwissen, spezifische Zeitfenster oder unzuverlässige Race Conditions.
PRN
Keine (Unauthenticated)
Vollständig unauthentifiziert ohne Benutzerkonto exploitbar.
UIR
Erforderlich (Click/Phishing)
Ein Opfer muss eine präparierte Datei öffnen oder einen Link anklicken.
SC
Verändert (Scope Changed)
Kann auf übergeordnete Systeme oder Hypervisor/Cloud-Ebene übergreifen (Sandbox Escape).
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IL
Gering (Teilweise)
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

Kritischer Zero-Day / Ohne Upstream-Patch
Handlungsempfehlung für Administratoren

Wird aktiv im Feld ausgenutzt! Kein verifiziertes Hersteller-Update gemeldet. Sofortige Quarantäne oder WAF-Virtual-Patching zwingend.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten jQuery End of Life: What's Actually EOL (and What Isn't)

Thematisch verwandte Begriffe: jQuery, Life, Whats, Actually · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag