Cross-Site Scripting Vulnerability in Bootstrap Web Framework
CVE-2025-1647

5.6MEDIUM

Key Information:

Vendor

Bootstrap

Status
Vendor
CVE Published:
15 May 2025

What is CVE-2025-1647?

A vulnerability has been identified in the Bootstrap framework, specifically an improper neutralization of input during web page generation, leading to Cross-Site Scripting (XSS). This issue affects several versions of Bootstrap prior to 4.0.0, allowing attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and session integrity.

Affected Version(s)

Bootstrap 3.4.1 < 4.0.0

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Johan Carlsson (joaxcar)
.