bootstrap is vulnerable to Cross-site Scripting (XSS)
62
Medium Risk
Affected versions of this package are vulnerable to Cross-site Scripting (XSS): a flaw in the data-loading-text attribute of the Bootstrap button plugin (versions ≥ 1.4.0 to ≤ 3.4.1) allows malicious JavaScript to be injected and executed, for example when the button enters its loading state.
You are affected if you are using a version that falls within the vulnerable range.
bootstrap is vulnerable to Cross-site Scripting (XSS) in versions 1.4.0 - 3.4.1.
To fix this vulnerability, upgrade to a later, supported version of Bootstrap, as version 3 is end-of-life and no longer receives security updates.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant