Releases94
Frequency1 month 3 weeks
Last Release
Stars174K
The most popular HTML, CSS, and JavaScript framework for developing responsive, mobile first projects on the web.

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

4.3 MEDIUM

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

4.3 MEDIUM

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

4.3 MEDIUM

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

4.3 MEDIUM

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

4.3 MEDIUM

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

4.3 MEDIUM

In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.