← Vulnerability feed

Vulnerability record · CVE-2018-14041 · published 13 July 2018

CVE-2018-14041: Getbootstrap bootstrap cross-site scripting vulnerability

Getbootstrap · Bootstrap

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

6.1 CVSS 3.0 Medium EPSS 4.3% · top 9.2% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
http://seclists.org/fulldisclosure/2019/May/10
http://seclists.org/fulldisclosure/2019/May/11
http://seclists.org/fulldisclosure/2019/May/13
https://access.redhat.com/errata/RHSA-2019:1456
https://blog.getbootstrap.com/2018/07/12/bootstrap-4-1-2/ Vendor Advisory
https://github.com/twbs/bootstrap/issues/26423 Issue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/issues/26627 ExploitIssue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/pull/26630 Issue TrackingPatchThird Party Advisory
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%
https://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e%40%3Cdev.superset.apache.o
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.o
https://lists.apache.org/thread.html/r3dc0cac8d856bca02bd6997355d7ff83027dcfc82f8646a29b89b714%40%3Cissues.hbase.apache.
https://seclists.org/bugtraq/2019/May/18
https://www.oracle.com/security-alerts/cpuApr2021.html
http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
http://seclists.org/fulldisclosure/2019/May/10
http://seclists.org/fulldisclosure/2019/May/11
http://seclists.org/fulldisclosure/2019/May/13
https://access.redhat.com/errata/RHSA-2019:1456
https://blog.getbootstrap.com/2018/07/12/bootstrap-4-1-2/ Vendor Advisory
https://github.com/twbs/bootstrap/issues/26423 Issue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/issues/26627 ExploitIssue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/pull/26630 Issue TrackingPatchThird Party Advisory
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%
https://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e%40%3Cdev.superset.apache.o
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.o
https://lists.apache.org/thread.html/r3dc0cac8d856bca02bd6997355d7ff83027dcfc82f8646a29b89b714%40%3Cissues.hbase.apache.
https://seclists.org/bugtraq/2019/May/18
https://www.oracle.com/security-alerts/cpuApr2021.html

Track CVE-2018-14041 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2019-8331Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.EPSS 16%6.1CVE-2018-20676Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.EPSS 3.8%6.1CVE-2018-20677Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.EPSS 4.0%6.1CVE-2016-10735Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018…EPSS 4.0%6.1CVE-2018-14040Debian linux cross-site scripting vulnerabilityIn Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.EPSS 4.1%6.1CVE-2018-14042Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.EPSS 4.0%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2018-14041), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.