Releases4
Frequency2 months 3 weeks
Last Release
Bootstrap-table is a javascript plugin that makes it easy to add extended row information (by clicking on a row) in HTML tables with the help of Twitter Bootstrap.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 1.20.25.4 MEDIUM3.5 LOW

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

= *, < 1.19.1, <= 1.19.03.1 LOW4.3 MEDIUM

This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.