Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4204-1 | twitter-bootstrap3 security update |
EUVD |
EUVD-2025-15170 | Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components |
Github GHSA |
GHSA-q58r-hwc8-rm9j | Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components |
Sun, 01 Jun 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 16 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 15 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 May 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0. | |
| Title | XSS in Bootstrap title attribute for Tooltip and Popover | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HeroDevs
Published:
Updated: 2025-06-01T11:02:28.106Z
Reserved: 2025-02-24T18:35:21.344Z
Link: CVE-2025-1647
Updated: 2025-06-01T11:02:28.106Z
Status : Deferred
Published: 2025-05-15T17:15:47.993
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-1647
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA