GHSA-7mvr-5x2g-wfc8MediumCVSS 6.1

Bootstrap Cross-site Scripting vulnerability

Published
September 13, 2018
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.

🎯 Affected products13

  • rubygems/bootstrap:>= 4.0.0, < 4.1.2
  • rubygems/bootstrap:>= 2.3.0, < 3.4.0
  • npm/bootstrap:>= 4.0.0, < 4.1.2
  • npm/bootstrap:>= 2.3.0, < 3.4.0
  • maven/org.webjars:bootstrap:>= 4.0.0, < 4.1.2
  • maven/org.webjars:bootstrap:>= 2.3.0, < 3.4.0
  • composer/twbs/bootstrap:>= 4.0.0, < 4.1.2
  • composer/twbs/bootstrap:>= 2.3.0, < 3.4.0
  • nuget/bootstrap:>= 4.0.0, < 4.1.2
  • nuget/bootstrap:>= 2.3.0, < 3.4.0
  • rubygems/bootstrap-sass:>= 2.3.0, < 3.4.0
  • npm/bootstrap-sass:>= 2.0.4, < 3.4.0
  • nuget/bootstrap.sass:>= 4.0.0, < 4.1.2

🔗 References (24)