CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “getbootstrap”

8 vulnerabilities found for “getbootstrap”

CVE-2019-10842
CRITICAL9.8

Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare.

getbootstrap / bootstrap-sass
Network
Published Apr 4, 2019
CVE-2019-8331
MEDIUM6.1

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

f5 / big-ip_policy_enforcement_manager+55
Network
Published Feb 20, 2019
CVE-2018-20676
MEDIUM6.1

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

getbootstrap / bootstrap
Network
Published Jan 9, 2019
CVE-2018-20677
MEDIUM6.1

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

getbootstrap / bootstrap
Network
Published Jan 9, 2019
CVE-2016-10735
MEDIUM6.1

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

getbootstrap / bootstrap+1
Network
Published Jan 9, 2019
CVE-2018-14040
MEDIUM6.1

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

debian / debian_linux+11
Network
Published Jul 13, 2018
CVE-2018-14041
MEDIUM6.1

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

getbootstrap / bootstrap+9
Network
Published Jul 13, 2018
CVE-2018-14042
MEDIUM6.1

In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

getbootstrap / bootstrap+10
Network
Published Jul 13, 2018