Jquery Vulnerabilities
From Documentation
ZK framework includes a customized jQuery library. Replacing that bundled jQuery in ZK to solve its security vulnerability isn't an option. Because there are both zk-specific customizations and jQuery introduced additional breaking changes. You have to upgrade ZK.
9.1.0 or above | 3.5.1 | |
9.0.0 | 1.12.4 | |
8.6.4.1 |
1.10.2 with security patches |
You can check zk-bundled jQuery version by this js variable jq.fn.jquery
.