FlawAtlas
Search the atlas
CVE-2019-8331 Moderate

Bootstrap Vulnerable to Cross-Site Scripting

Versions of `bootstrap` prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The `data-template` attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript. ## Recommendation For `bootstrap` 4.x upgrade to 4.3.1 or later. For `bootstrap` 3.x upgrade to 3.4.1 or later.

Exploit probability 16.4%
Published February 22, 2019
Required by Not available
Last source change June 2, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

25 explicit affected versions

Maven org.webjars:bootstrap

31 explicit affected versions

NuGet Bootstrap.Less

6 explicit affected versions

NuGet bootstrap

24 explicit affected versions

NuGet bootstrap.sass

17 explicit affected versions

Packagist twbs/bootstrap

23 explicit affected versions

RubyGems bootstrap

18 explicit affected versions

RubyGems bootstrap-sass

24 explicit affected versions

RubyGems twitter-bootstrap-rails

46 explicit affected versions

npm bootstrap
npm bootstrap-sass

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-8331

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

View original source
Open Source Vulnerabilities GHSA-9v3m-8fp8-mj99

Versions of `bootstrap` prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The `data-template` attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript. ## Recommendation For `bootstrap` 4.x upgrade to 4.3.1 or later. For `bootstrap` 3.x upgrade to 3.4.1 or later.

View original source

05 / REFERENCES

Further evidence