JQuery’s Five-Year Itch: Old Bug Crawls Back to Haunt Cybersecurity!
CISA adds a patched jQuery security flaw to its KEV catalog due to active exploitation. This five-year-old vulnerability, CVE-2020-11023, is now making waves. The bug could lead to arbitrary code execution if left unchecked. Agencies are advised to take action by February 2025 to tighten their digital fortresses.

Hot Take:
Looks like jQuery’s old bug is back with a vengeance, proving once again that even in the world of cybersecurity, age is just a number – especially when it comes to vulnerabilities! While some folks are collecting vintage records, cybercriminals are dusting off vintage exploits. Who knew web security could be so retro?
Key Points:
- CISA added the five-year-old jQuery vulnerability to its Known Exploited Vulnerabilities catalog.
- The vulnerability, CVE-2020-11023, is a cross-site scripting (XSS) bug.
- jQuery version 3.5.0, released in April 2020, patched the flaw.
- EclecticIQ identified the flaw’s use in real-world attacks in 2024.
- FCEB agencies have until February 13, 2025, to address the vulnerability.
Already a member? Log in here