FlawAtlas
Search the atlas
CVE-2016-10735 Moderate

Bootstrap Cross-site Scripting vulnerability

In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info.

Exploit probability 4.0%
Published January 17, 2019
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

2 explicit affected versions

Maven org.webjars:bootstrap

33 explicit affected versions

NuGet bootstrap

19 explicit affected versions

NuGet bootstrap.sass

1 explicit affected versions

Packagist twbs/bootstrap

21 explicit affected versions

RubyGems bootstrap

11 explicit affected versions

RubyGems bootstrap-sass

42 explicit affected versions

npm bootstrap
npm bootstrap-sass

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2016-10735

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

View original source
Open Source Vulnerabilities GHSA-4p24-vmcr-4gqj

In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041. See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info.

View original source

05 / REFERENCES

Further evidence