Bootboxjs is a JavaScript library that provides modal and dialog-box functionality for web applications, with its vulnerability profile centered on the core bootbox product and input-sanitization issues in web-page generation. The durable signal reflects the library's role in rendering user-controlled or dynamically sourced content to the DOM, where improper neutralization of inputs can lead to cross-site scripting. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bootboxjs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46998MEDIUM Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() | Nov 7, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bootboxjs.
Media articles that mention a CVE ID that affects a product developed by Bootboxjs — matched by CVE ID, not by vendor name.