{"id":"CVE-2016-10735","aliases":["GHSA-4p24-vmcr-4gqj"],"url":"https://o3.security/vulnerability/CVE-2016-10735","summary":"Bootstrap Cross-site Scripting vulnerability","details":"In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.","published":"2019-01-09T05:29:00.883Z","modified":"2026-07-08T12:43:12.487670Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"org.webjars:bootstrap","fixedVersion":"3.4.0"},{"ecosystem":"Maven","name":"org.webjars:bootstrap","fixedVersion":"4.0.0-beta.2"},{"ecosystem":"npm","name":"bootstrap","fixedVersion":"3.4.0"},{"ecosystem":"npm","name":"bootstrap","fixedVersion":"4.0.0-beta.2"},{"ecosystem":"npm","name":"bootstrap-sass","fixedVersion":"3.4.0"},{"ecosystem":"NuGet","name":"bootstrap","fixedVersion":"3.4.0"},{"ecosystem":"NuGet","name":"bootstrap","fixedVersion":"4.0.0-beta.2"},{"ecosystem":"NuGet","name":"bootstrap.sass","fixedVersion":"4.0.0-beta.2"},{"ecosystem":"Packagist","name":"twbs/bootstrap","fixedVersion":"3.4.0"},{"ecosystem":"Packagist","name":"twbs/bootstrap","fixedVersion":"4.0.0-beta.2"},{"ecosystem":"RubyGems","name":"bootstrap","fixedVersion":"4.0.0-beta.2"},{"ecosystem":"RubyGems","name":"bootstrap-sass","fixedVersion":"3.4.0"}],"fix":{"url":"https://github.com/twbs/bootstrap/pull/23687","label":"twbs/bootstrap#23687"},"references":[{"type":"WEB","url":"https://www.tenable.com/security/tns-2021-14"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2019:1076"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2019:1570"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3023"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0132"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0133"},{"type":"ADVISORY","url":"https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/"},{"type":"ADVISORY","url":"https://github.com/twbs/bootstrap/pull/23679"},{"type":"ADVISORY","url":"https://github.com/twbs/bootstrap/pull/26460"},{"type":"REPORT","url":"https://github.com/twbs/bootstrap/issues/20184"},{"type":"REPORT","url":"https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906"},{"type":"FIX","url":"https://github.com/twbs/bootstrap/pull/23687"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:43:12.487670Z"}}