{"id":"CVE-2025-3573","aliases":["GHSA-rrj2-ph5q-jxw2"],"url":"https://o3.security/vulnerability/CVE-2025-3573","summary":"jquery-validation vulnerable to Cross-site Scripting","details":"Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.","published":"2025-04-15T05:00:09.474Z","modified":"2026-08-12T03:51:17.953148668Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"jquery-validation","fixedVersion":"1.20.0"}],"fix":{"url":"https://github.com/jquery-validation/jquery-validation/commit/7a490d8f39bd988027568ddcf51755e1f4688902","label":"jquery-validation/jquery-validation@7a490d8"},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERYVALIDATION-5952285"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3573.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3573"},{"type":"FIX","url":"https://github.com/jquery-validation/jquery-validation/commit/7a490d8f39bd988027568ddcf51755e1f4688902"},{"type":"FIX","url":"https://github.com/jquery-validation/jquery-validation/pull/2462"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:17.953148668Z"}}