twbs/bootstrap
Packagist7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting twbs/bootstrappage 1 of 1
- CVE-2016-10735MEDIUMCVSS 6.1EG 6.1fixed in 3.4.0 or 4.0.0-beta.2, by version range2019-01-09
vulnerable: v4.0.0-beta
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
- CVE-2018-14040MEDIUMCVSS 6.1EG 6.1fixed in 3.4.0 or 4.1.2, by version range2018-07-13
vulnerable: v4.0.0, v4.1.0, v4.1.1
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
- CVE-2018-14041MEDIUMCVSS 6.1EG 6.1fixed in 4.1.22018-07-13
vulnerable: v4.0.0, v4.1.0, v4.1.1
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
- CVE-2018-14042MEDIUMCVSS 6.1EG 6.1fixed in 4.1.2 or 3.4.0, by version range2018-07-13
vulnerable: v2.3.0 ... v3.3.7 (19 versions)
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
- CVE-2018-20676MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02019-01-09
vulnerable: v2.2.2 ... v3.3.7 (20 versions)
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
- CVE-2018-20677MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02019-01-09
vulnerable: v2.2.2 ... v3.3.7 (20 versions)
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
- CVE-2019-8331MEDIUMCVSS 6.1EG 6.1fixed in 3.4.1 or 4.3.1, by version range2019-02-20
vulnerable: v4.0.0 ... v4.3.0 (8 versions)
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Check whether twbs/bootstrap is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for twbs/bootstrap CVEs against the assets you own.
Book a Demo →