GHSA-9v3m-8fp8-mj99MediumCVSS 6.1

Bootstrap Vulnerable to Cross-Site Scripting

Published
February 22, 2019
Last Modified
June 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.

Recommendation

For bootstrap 4.x upgrade to 4.3.1 or later. For bootstrap 3.x upgrade to 3.4.1 or later.

🎯 Affected products14

  • rubygems/bootstrap:< 4.3.1
  • rubygems/bootstrap-sass:>= 3.0.0, < 3.4.1
  • nuget/Bootstrap.Less:>= 3.0.0, < 3.4.1
  • nuget/bootstrap:>= 4.0.0, < 4.3.1
  • nuget/bootstrap:>= 3.0.0, < 3.4.1
  • nuget/bootstrap.sass:< 4.3.1
  • npm/bootstrap:>= 4.0.0, < 4.3.1
  • npm/bootstrap:>= 3.0.0, < 3.4.1
  • npm/bootstrap-sass:>= 3.0.0, < 3.4.1
  • maven/org.webjars:bootstrap:>= 3.0.0, < 3.4.1
  • maven/org.webjars:bootstrap:>= 4.0.0, < 4.3.1
  • composer/twbs/bootstrap:>= 3.0.0, < 3.4.1
  • composer/twbs/bootstrap:>= 4.0.0, < 4.3.1
  • rubygems/twitter-bootstrap-rails:< 5.3.0

🔗 References (44)