{"id":"CVE-2021-23472","aliases":["GHSA-mw6q-98mp-g8g8"],"url":"https://o3.security/vulnerability/CVE-2021-23472","summary":"Cross-site Scripting in bootstrap-table","details":"This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.","published":"2021-11-03T18:15:08.010Z","modified":"2026-07-09T01:06:12.085480Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.02332,"percentile":0.81844,"asOf":"2026-07-31"},"cisaKev":null,"exploitsKnown":6,"affectedPackages":[{"ecosystem":"npm","name":"bootstrap-table","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/wenzhixin/bootstrap-table/blob/develop/src/utils/index.js%23L218"},{"type":"FIX","url":"https://security.snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1910690"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1910689"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBWENZHIXIN-1910687"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910688"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-BOOTSTRAPTABLE-1657597"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:06:12.085480Z"}}