GHSA-q58r-hwc8-rm9jMediumCVSS 5.6

Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components

Published
May 15, 2025
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS). This issue affects Bootstrap version 3.4.1. At time of publication, there is no publicly available patched version.

🎯 Affected products1

  • npm/bootstrap:= 3.4.1

🔗 References (5)