bootstrap-sass
bootstrap-sass is a Sass-powered version of Bootstrap 3, ready to drop right into your Sass powered applications.
Activity
- Latest release
- 7y ago
- Total releases
- 59
- Cadence
- ~20 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Sep 06, 2011
| Version | Released | |
|---|---|---|
3.2.0.4
minor
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.2.0.4
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.4.1
patch
|
3.4.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.4.0
minor
1 CVE
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.4.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.3.7
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.7
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.6
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.6
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.5.1
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.5.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.5
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.5
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.4.1
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.4.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.3
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.2.1
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.2.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.2.0
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.2.0
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.1.0
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.1.0
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.0.1
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.0.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.0.0
minor
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.3.0.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.1.1.1
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.1.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.1.1.0
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.1.0
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.1.0.2
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.1.0.1
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.1.0.0
minor
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.0.3.0
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.3.0
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.2.1
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.2.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.1.0
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.1.0
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.2.0
patch
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.2.0
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.1.0.rc
pre
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.1.0.rc
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.0.0
major
6 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
3.0.0.0
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
+ 12 more Show less
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
3.4.0
Fixed in
3.4.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.0
major
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.0.0.rc2
pre
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.0.rc2
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.0.0.0.rc
pre
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0.0.rc
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.3.2.2
patch
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.2.1
patch
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.2.0
patch
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.1.3
patch
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.1.2
patch
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.1.0
patch
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.0.1
patch
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.3.0.0
minor
5 CVEs
CVE-2018-14040
GHSA-3wqf-4x89-9g79
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-14042
GHSA-7mvr-5x2g-wfc8
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041. Affected versions
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
+ 21 more Show less
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.2.0
patch
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.1.1
patch
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.1.0
minor
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.1.0
patch
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0.1
patch
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0.0
minor
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.4.2
patch
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.4.1
patch
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.4.0
patch
3 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2016-10735
GHSA-4p24-vmcr-4gqj
Jan 17, 2019
Bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info. Affected versions
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
+ 30 more Show less
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.3.1
patch
2 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.3
patch
2 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.2
patch
2 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.1
patch
2 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0
major
2 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.4
patch
2 CVEs
CVE-2018-20677
GHSA-ph58-4vrj-w6hr
Jan 17, 2019
bootstrap Cross-site Scripting vulnerability
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-20676
GHSA-3mgp-fx93-9xv5
Jan 17, 2019
XSS vulnerability that affects bootstrap
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. Affected versions
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
2.0.0
2.0.1
+ 45 more Show less
2.0.2
2.0.3
2.0.3.1
2.0.4.0
2.0.4.1
2.0.4.2
2.1.0.0
2.1.0.1
2.1.1.0
2.2.1.0
2.2.1.1
2.2.2.0
2.3.0.0
2.3.0.1
2.3.1.0
2.3.1.2
2.3.1.3
2.3.2.0
2.3.2.1
2.3.2.2
3.0.0.0
3.0.0.0.rc
3.0.0.0.rc2
3.0.1.0
3.0.1.0.rc
3.0.2.0
3.0.2.1
3.0.3.0
3.1.0.0
3.1.0.1
3.1.0.2
3.1.1.0
3.1.1.1
3.2.0.4
3.3.0.0
3.3.0.1
3.3.1.0
3.3.2.0
3.3.2.1
3.3.3
3.3.4.1
3.3.5
3.3.5.1
3.3.6
3.3.7
Fixed in
3.4.0
References
Updated Sep 10, 2026 · Source: OSV.dev |