In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
We have discovered 458,137 live websites that are affected by CVE-2018-14040.
| Product | |
| Category | UI Frameworks |
| Vulnerable Domains | 458,137 live websites (51% of Bootstrap install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 83 versions ( 48% of all versions) |
| 181,802 websites | |
| 27,807 websites | |
| 18,890 websites | |
| 17,765 websites | |
| 17,226 websites | |
| 14,979 websites | |
| 14,107 websites | |
| 10,692 websites | |
| 9,891 websites | |
| 9,547 websites |
| .com | 203,810 websites |
| .org | 22,497 websites |
| .net | 15,860 websites |
| .de | 14,731 websites |
| .co.uk | 12,856 websites |
| .nl | 12,666 websites |
| .ru | 11,647 websites |
| .com.br | 9,781 websites |
| .fr | 7,789 websites |
| .it | 7,616 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.****.br | ** | ||
| ********.com | *** | ||
| ******.com | *** | ||
| **.com | *** | ||
| *********.com | *** | ||
| *********.com | *** | ||
| *****.******.com | *,*** | ||
| ****.org | *,*** | ||
| *******.com | *,*** | ||
| ************.com | *,*** |