bootstrap@4.1.2 vulnerabilities

The most popular front-end framework for developing responsive, mobile first projects on the web.

Direct Vulnerabilities

Known vulnerabilities in the bootstrap package. This does not include vulnerabilities belonging to this package’s dependencies.

Cross-site Scripting (XSS)

bootstrap is a popular front-end framework for faster and easier web development.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in data-template, data-content and data-title properties of tooltip/popover.

How to fix Cross-site Scripting (XSS)?

Upgrade bootstrap to version 3.4.1, 4.3.1 or higher.

<3.4.1 >=4.0.0 <4.3.1