Skip to content
Noroxi

getbootstrap records

9 published records for vendor getbootstrap.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19
  3. 24

Bar: total · dark part: CISA KEV.

Attack profile

All records

9 records
  • Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org.

    CriticalCVSS 9.8No exploitEPSS 5%

    getbootstrap · bootstrap-sassApr 4, 2019

  • CVE-2019-8331
    29Monitor

    In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

    MediumCVSS 6.1Proof of conceptEPSS 16%

    getbootstrap · bootstrapFeb 20, 2019

  • In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

    MediumCVSS 6.1Proof of conceptEPSS 4%

    getbootstrap · bootstrapJul 13, 2018

  • In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

    MediumCVSS 6.1Proof of conceptEPSS 4%

    debian · debian linuxJul 13, 2018

  • In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than

    MediumCVSS 6.1Proof of conceptEPSS 4%

    getbootstrap · bootstrapJan 9, 2019

  • In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

    MediumCVSS 6.1Proof of conceptEPSS 4%

    getbootstrap · bootstrapJul 13, 2018

  • In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

    MediumCVSS 6.1No exploitEPSS 4%

    getbootstrap · bootstrapJan 9, 2019

  • In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

    MediumCVSS 6.1No exploitEPSS 4%

    getbootstrap · bootstrapJan 9, 2019

  • CVE-2024-6485
    25Monitor

    XSS in Bootstrap button component

    MediumCVSS 6.4Proof of conceptEPSS 0%

    bootstrap · bootstrapJul 11, 2024