Getbootstrap Bootstrap vulnerabilities
7 known vulnerabilities affecting getbootstrap/bootstrap.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2019-8331MEDIUMCVSS 6.1fixed in 3.4.1≥ 4.3.0, < 4.3.12019-02-20
CVE-2019-8331 [MEDIUM] CWE-79 CVE-2019-8331: In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-tem
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
ghsanvdosv
CVE-2018-20676MEDIUMCVSS 6.1fixed in 3.4.02019-01-09
CVE-2018-20676 [MEDIUM] CWE-79 CVE-2018-20676: In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
ghsanvdosv
CVE-2016-10735MEDIUMCVSS 6.1≥ 3.0.0, < 3.4.0v4.0.02019-01-09
CVE-2016-10735 [MEDIUM] CWE-79 CVE-2016-10735: In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target a
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
ghsanvdosv
CVE-2018-20677MEDIUMCVSS 6.1fixed in 3.4.02019-01-09
CVE-2018-20677 [MEDIUM] CWE-79 CVE-2018-20677: In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
ghsanvdosv
CVE-2018-14042MEDIUMCVSS 6.1fixed in 3.4.0≥ 4.0.0, < 4.1.2+1 more2018-07-13
CVE-2018-14042 [MEDIUM] CWE-79 CVE-2018-14042: In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
ghsanvdosv
CVE-2018-14041MEDIUMCVSS 6.1≥ 4.0.0, < 4.1.2v4.0.02018-07-13
CVE-2018-14041 [MEDIUM] CWE-79 CVE-2018-14041: In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
ghsanvdosv
CVE-2018-14040MEDIUMCVSS 6.1fixed in 3.4.0≥ 4.0.0, < 4.1.2+1 more2018-07-13
CVE-2018-14040 [MEDIUM] CWE-79 CVE-2018-14040: In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
ghsanvdosv