Bootstrap is a widely embedded front-end framework whose vulnerability footprint, while narrow in product scope, carries outsized impact due to its pervasive use across web applications and downstream projects. Its disclosed vulnerabilities skew toward serious outcomes and recur through input-handling and code-generation weaknesses—chiefly cross-site scripting and code injection flaws—that reflect the framework's role in parsing and rendering user-supplied content. Defenders should treat Bootstrap advisories as broadly applicable across their web portfolio; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getbootstrap over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10842CRITICAL Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie | Apr 4, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-8331MEDIUM In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. | Feb 20, 2019 | 6.1 | 27 | NO | NO |
CVE-2018-20677MEDIUM In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. | Jan 9, 2019 | 6.1 | 23 | NO | NO |
CVE-2018-20676MEDIUM In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. | Jan 9, 2019 | 6.1 | 23 | NO | NO |
CVE-2016-10735MEDIUM In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041. | Jan 9, 2019 | 6.1 | 23 | NO | NO |
CVE-2018-14042MEDIUM In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. | Jul 13, 2018 | 6.1 | 23 | NO | NO |
CVE-2018-14041MEDIUM In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. | Jul 13, 2018 | 6.1 | 23 | NO | NO |
CVE-2018-14040MEDIUM In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. | Jul 13, 2018 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getbootstrap.
Media articles that mention a CVE ID that affects a product developed by Getbootstrap — matched by CVE ID, not by vendor name.