The most popular front-end framework for developing responsive, mobile first projects on the web.
76%
Total Score
64
100
100
65
50
| Title | Versions | Severity |
|---|---|---|
CVE-2025-1647 bootstrap is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.4.1 - 3.4.1. | 3.4.1 - 3.4.1 | Medium |
CVE-2024-6531 bootstrap is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 4.6.2, 4.0.0 - 4.6.2 and 4.0.0 - 4.6.2. | 4.0.0 - 4.6.2 | Medium |
CVE-2024-6485 bootstrap is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.4.0 - 3.4.1. | 1.4.0 - 3.4.1 | Medium |
CVE-2024-6484 bootstrap is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 3.4.1, 2.0.0 - 3.4.1 and 2.0.0 - 3.4.1. | 2.0.0 - 3.4.1 | Medium |
CVE-2018-14040 bootstrap is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 4.1.2, 4.0.0 - 4.1.2, 2.3.0 - 3.4.0, 2.3.0 - 3.4.0, 2.3.0 - 3.4.0 and 4.0.0 - 4.1.2. | 2.3.0 - 3.4.04.0.0 - 4.1.2 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant