twitter-bootstrap-rails
Twitter Bootstrap for Rails 8
Activity
- Latest release
- 1mo ago
- Total releases
- 49
- Cadence
- ~16 days
- Last 12 months
- 3
Reach
- Downloads
- 11.1M
- Stars
- 4.5k
Details
- License
- MIT
- First release
- Aug 22, 2011
| Version | Released | |
|---|---|---|
5.4.0
minor
| ||
5.3.1
patch
| ||
5.3.0
minor
| ||
5.1.0
minor
1 CVE
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.1.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
5.0.0
major
1 CVE
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.0.0
major
Dependencies (7)
Changelog
Compare changes
|
|
4.0.0
major
1 CVE
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
4.0.0
major
Dependencies (7)
Changelog
Compare changes
|
|
3.2.2
patch
1 CVE
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.2.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
3.2.1.rc1
pre
1 CVE
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.2.1.rc1
pre
Dependencies (7)
Changelog
Compare changes
|
|
3.2.0
major
1 CVE
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.8
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.7
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.6
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.5
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.4
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.3
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.1
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.0
minor
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.9
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.8
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.7
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.6
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.5
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.4
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.2
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.3
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.1
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0
minor
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.9
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.8
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.7
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.6
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.5
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.4
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.3
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.1.0
unknown
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.2
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.1
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0
unknown
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0rc0
pre
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0
major
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.3
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.2
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.1
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.0
minor
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.1
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.0
major
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.0.5
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.0.4
patch
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.0.3
initial
2 CVEs
CVE-2014-4920
GHSA-vpqv-mqvc-pcx2
Mar 16, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
Medium
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 28 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
Fixed in
3.2.0
References Updated Nov 30, 2024 · Source: OSV.dev
CVE-2019-8331
GHSA-9v3m-8fp8-mj99
Feb 22, 2019
Bootstrap Vulnerable to Cross-Site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Versions of RecommendationFor Affected versions
0.0.3
0.0.4
0.0.5
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0
2.0.0
2.0.1
+ 34 more Show less
2.0.1.0
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0rc0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
3.2.0
3.2.1.rc1
3.2.2
4.0.0
5.0.0
5.1.0
Fixed in
5.3.0
References
Updated Sep 10, 2026 · Source: OSV.dev |