LiveActive security incident?Get immediate response
CVE Record

CVE-2018-18405: jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.

jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This entry claims jQuery 2.2.2 could allow cross-site scripting through an image error attribute. The CVE record itself says the report has been described as a spam entry, and it provides no CVSS score, CWE, or reliable affected-product detail. Treat it as a low-evidence inventory and hygiene issue, not a confirmed emergency.

Executive priority

Do not treat this as a board-level incident based on current evidence. Assign normal vulnerability-management priority to confirm whether legacy jQuery 2.2.2 exists and whether vendor-supported updates are available.

Technical view

The bundled CVE data describes XSS in jQuery v2.2.2 involving an IMG onerror attribute, but affected vendor/product fields are n/a and severity is unknown. The record flags the report as possibly spam. Fedora published a related package announcement, but the bundle does not establish broad vulnerable versions, exploitability, or a canonical upstream fix.

Likely exposure

Exposure is only plausible where applications still include jQuery 2.2.2 and process untrusted HTML or attributes into the DOM. The source bundle does not prove exposure for all jQuery consumers or name affected downstream products beyond a Fedora package advisory reference.

Exploitation context

No active exploitation is supported by the provided sources. The CVE is not in KEV, and the record contains an explicit note questioning the report quality. Do not assume weaponized exploitation without stronger vendor or threat-intelligence confirmation.

Researcher notes

The key issue is evidence quality. The CVE description names an XSS pattern but also says the vulnerability was reported as spam. There is no CVSS vector, CWE, reliable CPE, or KEV status. Researchers should preserve that uncertainty when triaging scanners or advisories.

Mitigation direction

  • Inventory applications and packages for jQuery 2.2.2 usage.
  • Check jQuery, OS vendor, and Fedora package guidance before changing versions.
  • Prefer maintained jQuery releases or supported distribution packages where compatible.
  • Sanitize untrusted HTML before DOM insertion.
  • Use Content Security Policy as defense-in-depth, not as the primary fix.

Validation and detection

  • Review SBOMs, lockfiles, and static assets for jQuery 2.2.2.
  • Identify code paths inserting user-controlled HTML into pages.
  • Check whether distribution packages include vendor backports or patches.
  • Record the CVE spam-entry caveat in vulnerability tracking.
  • Avoid production exploit testing; validate with safe code review and dependency evidence.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-18405 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
5Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.