jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life.
Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issue that may affect Drupal 9 and 7:
CVE-2021-41184: XSS in the `of` option of the `.position()` util
It is possible that this vulnerability is exploitable with some Drupal modules. As a precaution, this Drupal security release applies the fix for the above cross-site description issue, without making any of the other changes to the jQuery version that is included in Drupal.
This advisory is not covered by Drupal Steward.
Install the latest version:
If you are using Drupal 9.3, update to Drupal 9.3.3.
If you are using Drupal 9.2, update to Drupal 9.2.11.
If you are using Drupal 7, update to Drupal 7.86.
All versions of Drupal 8 and 9 prior to 9.2.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.
Chris of the Drupal Security Team
Drew Webber of the Drupal Security Team
Alex Bronstein of the Drupal Security Team
Ben Mullins
xjm of the Drupal Security Team
Théodore Biadala
More Stories
cri-o1.31-1.31.7-1.fc43
FEDORA-2025-556d8c02d7 Packages in this update: cri-o1.31-1.31.7-1.fc43 Update description: Automatic update for cri-o1.31-1.31.7-1.fc43. Changelog * Wed Apr 2 2025 Bradley G...
zabbix-7.2.5-1.fc42
FEDORA-2025-700a59e277 Packages in this update: zabbix-7.2.5-1.fc42 Update description: Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700) Read More
zabbix7.0-7.0.11-1.el8
FEDORA-EPEL-2025-01e745cb85 Packages in this update: zabbix7.0-7.0.11-1.el8 Update description: Update to 7.0.11 CVE-2024-36465, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699, CVE-2024-45700 Re-install SELinux module in...
zabbix7.0-7.0.11-1.el9
FEDORA-EPEL-2025-80a466f7f5 Packages in this update: zabbix7.0-7.0.11-1.el9 Update description: Update to 7.0.11 CVE-2024-36465, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699, CVE-2024-45700 Re-install SELinux module in...
zabbix6.0-6.0.39-1.el8
FEDORA-EPEL-2025-77875be662 Packages in this update: zabbix6.0-6.0.39-1.el8 Update description: Update to 6.0.39 CVE-2024-45700, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699 Fix selinux module name in...
zabbix-7.0.11-1.fc41
FEDORA-2025-a7a06a72c8 Packages in this update: zabbix-7.0.11-1.fc41 Update description: Update to 7.0.11 CVE-2024-36465, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699, CVE-2024-45700 Read More