{"id":"CVE-2022-1726","aliases":["GHSA-grw5-g9h2-wpg8"],"url":"https://o3.security/vulnerability/CVE-2022-1726","summary":"Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in wenzhixin/bootstrap-table","details":"Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.","published":"2022-05-16T14:55:18Z","modified":"2026-07-15T01:49:00.306358635Z","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"bootstrap-table","fixedVersion":"1.20.2"}],"fix":{"url":"https://github.com/wenzhixin/bootstrap-table/commit/b4a1e5dd332be652e0bc376fd9256886cf4bbde9","label":"wenzhixin/bootstrap-table@b4a1e5d"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/9b85cc33-0395-4c31-8a42-3a94beb2efea"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1726.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1726"},{"type":"FIX","url":"https://github.com/wenzhixin/bootstrap-table/commit/b4a1e5dd332be652e0bc376fd9256886cf4bbde9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:00.306358635Z"}}