Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components
Moderate severity
GitHub Reviewed
Published
May 15, 2025
to the GitHub Advisory Database
•
Updated Sep 18, 2025
Description
Published by the National Vulnerability Database
May 15, 2025
Published to the GitHub Advisory Database
May 15, 2025
Reviewed
Sep 18, 2025
Last updated
Sep 18, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS). This issue affects Bootstrap version 3.4.1. At time of publication, there is no publicly available patched version.
References