jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry
https://twitter.com/DanielRufde/status/1255185961866145792
https://gitter.im/jquery/jquery?at=5ea844a05cd4fe50a3d7ddc9
https://gist.github.com/CyberSecurityUP/26c5b032897630fe8407da4a8ef216d4