Search CVE reports
1 – 10 of 11 results
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.
1 affected package
twitter-bootstrap3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap3 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through...
2 affected packages
twitter-bootstrap3, twitter-bootstrap4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap3 | Not affected | Not affected | Not affected | Not affected |
twitter-bootstrap4 | Fixed | Fixed | Fixed | — |
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can...
1 affected package
twitter-bootstrap3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap3 | Fixed | Fixed | Fixed | Fixed |
A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through...
2 affected packages
twitter-bootstrap3, twitter-bootstrap4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap3 | Fixed | Fixed | Fixed | Fixed |
twitter-bootstrap4 | Not affected | Not affected | Not affected | — |
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
3 affected packages
twitter-bootstrap, twitter-bootstrap3, twitter-bootstrap4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap | Not in release | Not in release | Not in release | Needs evaluation |
twitter-bootstrap3 | Not affected | Not affected | Not affected | Vulnerable |
twitter-bootstrap4 | Not affected | Not affected | Not affected | Not in release |
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
3 affected packages
twitter-bootstrap, twitter-bootstrap3, twitter-bootstrap4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap | Not in release | Not in release | Not in release | Needs evaluation |
twitter-bootstrap3 | Not affected | Not affected | Not affected | Vulnerable |
twitter-bootstrap4 | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
3 affected packages
twitter-bootstrap, twitter-bootstrap3, twitter-bootstrap4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap | Not in release | Not in release | Not in release | Needs evaluation |
twitter-bootstrap3 | Not affected | Not affected | Not affected | Vulnerable |
twitter-bootstrap4 | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
Some fixes available 13 of 16
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
3 affected packages
twitter-bootstrap, twitter-bootstrap3, twitter-bootstrap4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap | Not in release | Not in release | Not in release | Not affected |
twitter-bootstrap3 | Fixed | Fixed | Fixed | Vulnerable |
twitter-bootstrap4 | Not affected | Not affected | Not affected | Not in release |
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
2 affected packages
twitter-bootstrap, twitter-bootstrap3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap | Not in release | Not in release | Not in release | Needs evaluation |
twitter-bootstrap3 | Not affected | Not affected | Not affected | Vulnerable |
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
2 affected packages
twitter-bootstrap, twitter-bootstrap3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
twitter-bootstrap | — | — | — | Not affected |
twitter-bootstrap3 | — | — | — | Not affected |