Jquery Vulnerabilities
From Documentation
ZK framework includes a customized jQuery library. Replacing that bundled jQuery in ZK to solve its security vulnerability isn't an option. This is because ZK and jQuery are deeply integrated with zk-specific customizations. Also, JQuery introduces breaking changes between major versions. Simply replacing jQuery won’t work.
To address this, please upgrade ZK to a patched or non-affected version.
| 9.1.0 or above | 3.5.1 |
|
| 9.0.0 | 1.12.4 | |
|
8.6.4.1 |
1.10.2 with security patches |
|
You can check the zk-bundled jQuery version by this JS variable jq.fn.jquery.