CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded. | ||||
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. | 6.1 |
Medium |
||
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041. | 6.1 |
Medium |
||
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. | 6.1 |
Medium |
||
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. | 6.1 |
Medium |
||
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. | 6.1 |
Medium |
||
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. | 6.1 |
Medium |