Intel

AIKIDO-2025-10716

jquery.datatables is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2021-23445 Published Oct 14, 2025

61

Medium Risk

This Affects:

DOTNETjquery.datatables
0.0.1 - 1.10.15
Fixed in 1.11.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). If an array is passed to the HTML escape entities function it would not have its contents escaped. jquery.datatables is unmaintained and no longer receiving security updates, so it it is recommended to migrate to the datatables.net library version 1.11.3 or later.

Who does this affect?

You are affected if you are using the jquery.datatables package.

Background info

jquery.datatables is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 1.10.15.

How to fix this

Migrate to the datatables.net library version 1.11.3 or later.