Staging #2132
Staging #2132
72 new alerts including 2 critical severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 2 critical
- 57 high
- 13 medium
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check warning on line 443 in wp/wp-admin/js/edit-comments.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check warning on line 220 in wp/wp-admin/js/inline-edit-post.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check warning on line 1023 in wp/wp-admin/js/nav-menu.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check warning on line 1426 in wp/wp-admin/js/nav-menu.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check warning on line 433 in wp/wp-admin/js/user-profile.js
Code scanning / CodeQL
DOM text reinterpreted as HTML Medium
is reinterpreted as HTML without escaping meta-characters.
Check failure on line 457 in wp/wp-includes/js/jquery/jquery.form.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 834 in wp/wp-includes/js/jquery/jquery.form.js
Code scanning / CodeQL
XML internal entity expansion High
without guarding against uncontrolled entity expansion.
Check failure on line 917 in wp/wp-includes/js/jquery/jquery.form.js
Code scanning / CodeQL
XML external entity expansion Critical
without guarding against external entity expansion.
Check failure on line 917 in wp/wp-includes/js/jquery/jquery.form.js
Code scanning / CodeQL
XML internal entity expansion High
without guarding against uncontrolled entity expansion.
Check failure on line 920 in wp/wp-includes/js/jquery/jquery.form.js
Code scanning / CodeQL
XML internal entity expansion High
without guarding against uncontrolled entity expansion.
Check failure on line 920 in wp/wp-includes/js/jquery/jquery.form.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 927 in wp/wp-includes/js/jquery/jquery.form.js
Code scanning / CodeQL
Code injection Critical
.
Check failure on line 1343 in wp/wp-includes/js/jquery/jquery.form.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 2652 in wp/wp-includes/js/jquery/jquery.js
Code scanning / CodeQL
Unvalidated dynamic method call High
name may dispatch to unexpected target and cause an exception.
Check failure on line 10175 in wp/wp-includes/js/jquery/jquery.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 444 in wp/wp-includes/js/jquery/ui/accordion.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 215 in wp/wp-includes/js/jquery/ui/autocomplete.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 207 in wp/wp-includes/js/jquery/ui/button.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 248 in wp/wp-includes/js/jquery/ui/checkboxradio.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 509 in wp/wp-includes/js/jquery/ui/core.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 1332 in wp/wp-includes/js/jquery/ui/core.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 1356 in wp/wp-includes/js/jquery/ui/core.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 1357 in wp/wp-includes/js/jquery/ui/core.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 1563 in wp/wp-includes/js/jquery/ui/core.js
Code scanning / CodeQL
Client-side cross-site scripting High
.
Check failure on line 1634 in wp/wp-includes/js/jquery/ui/core.js
Code scanning / CodeQL
Client-side cross-site scripting High
.