CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded. | ||||
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. | 6.1 |
Medium |
||
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. | 6.1 |
Medium |
||
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. | 6.1 |
Medium |