← Vulnerability feed

Vulnerability record · CVE-2018-20677 · published 9 January 2019

CVE-2018-20677: Getbootstrap bootstrap cross-site scripting vulnerability

Getbootstrap · Bootstrap

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

6.1 CVSS 3.0 Medium EPSS 4.0% · top 9.9% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://access.redhat.com/errata/RHBA-2019:1076
https://access.redhat.com/errata/RHBA-2019:1570
https://access.redhat.com/errata/RHSA-2019:1456
https://access.redhat.com/errata/RHSA-2019:3023
https://access.redhat.com/errata/RHSA-2020:0132
https://access.redhat.com/errata/RHSA-2020:0133
https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ Release NotesVendor Advisory
https://github.com/twbs/bootstrap/issues/27045 ExploitIssue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906 Issue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/issues/27915#issuecomment-452196628 Issue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/pull/27047 PatchThird Party Advisory
https://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e%40%3Cdev.superset.apache.o
https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apach
https://www.tenable.com/security/tns-2021-14
https://access.redhat.com/errata/RHBA-2019:1076
https://access.redhat.com/errata/RHBA-2019:1570
https://access.redhat.com/errata/RHSA-2019:1456
https://access.redhat.com/errata/RHSA-2019:3023
https://access.redhat.com/errata/RHSA-2020:0132
https://access.redhat.com/errata/RHSA-2020:0133
https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ Release NotesVendor Advisory
https://github.com/twbs/bootstrap/issues/27045 ExploitIssue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906 Issue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/issues/27915#issuecomment-452196628 Issue TrackingThird Party Advisory
https://github.com/twbs/bootstrap/pull/27047 PatchThird Party Advisory
https://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e%40%3Cdev.superset.apache.o
https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apach
https://www.tenable.com/security/tns-2021-14

Track CVE-2018-20677 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2019-8331Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.EPSS 16%6.1CVE-2018-20676Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.EPSS 3.8%6.1CVE-2016-10735Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018…EPSS 4.0%6.1CVE-2018-14040Debian linux cross-site scripting vulnerabilityIn Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.EPSS 4.1%6.1CVE-2018-14041Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.EPSS 4.3%6.1CVE-2018-14042Getbootstrap bootstrap cross-site scripting vulnerabilityIn Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.EPSS 4.0%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2018-20677), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.