Bootstrap Getbootstrap Bootstrap

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Getbootstrap Bootstrap.

By the Year

In 2026 there have been 0 vulnerabilities in Getbootstrap Bootstrap. Bootstrap did not have any published security vulnerabilities last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 1 6.40
2023 0 0.00
2022 1 6.10
2021 0 0.00
2020 0 0.00
2019 4 6.10
2018 3 0.00

It may take a day or so for new Bootstrap vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Getbootstrap Bootstrap Security Vulnerabilities

Bootstrap XSS via data-loading-text in Button plugin
CVE-2024-6485 6.4 - Medium - July 11, 2024

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

XSS

Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability
CVE-2022-26624 6.1 - Medium - April 08, 2022

Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.

XSS

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1
CVE-2019-8331 - February 20, 2019

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

In Bootstrap before 3.4.0
CVE-2018-20676 - January 09, 2019

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

In Bootstrap before 3.4.0
CVE-2018-20677 - January 09, 2019

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2
CVE-2016-10735 6.1 - Medium - January 09, 2019

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

XSS

In Bootstrap before 4.1.2
CVE-2018-14040 - July 13, 2018

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

In Bootstrap before 4.1.2
CVE-2018-14041 - July 13, 2018

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

In Bootstrap before 4.1.2
CVE-2018-14042 - July 13, 2018

In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Getbootstrap Bootstrap or by Getbootstrap? Click the Watch button to subscribe.

subscribe