Skip to content
RequestGuard Vulnerabilities
Pricing

CVE record

CVE-2016-10735

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

CVE evidence

Known exploitation

Not listed in fetched KEV catalog

Absence from the fetched catalog does not establish that exploitation has not occurred.

Severity

moderate

CVSS 6.1 ยท CVSS_V3

Affected packages

4

Supported package records returned by OSV. Vendor and product names are not used to infer matches.

OSV package mapping

Affected open-source packages

PackageEcosystemFixed versions
bootstrapnpm3.4.0, 4.0.0-beta.2
org.webjars:bootstrapmaven3.4.0, 4.0.0-beta.2
twbs/bootstrapcomposer3.4.0, 4.0.0-beta.2
bootstrap-sassnpm3.4.0