In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
We have discovered 1,222,580 live websites that are affected by CVE-2018-14040.
Product | ![]() |
Category | UI Frameworks |
Vulnerable Domains | 1,222,580 live websites (55.92% of Bootstrap install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 246 versions ( 49.00% of all versions) |
![]() | 536,925 websites |
![]() | 91,167 websites |
![]() | 67,523 websites |
![]() | 44,490 websites |
![]() | 44,223 websites |
![]() | 35,678 websites |
![]() | 30,983 websites |
![]() | 27,581 websites |
![]() | 24,340 websites |
![]() | 22,185 websites |
.com | 555,792 websites |
.org | 58,576 websites |
.de | 43,732 websites |
.net | 38,093 websites |
.nl | 31,424 websites |
.co.uk | 30,445 websites |
.ru | 27,244 websites |
.com.br | 26,355 websites |
.fr | 24,911 websites |
.pl | 21,543 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.****.br | ![]() | ** | |
********.com | ![]() | *** | |
******.com | ![]() | *** | |
**.com | ![]() | *** | |
*********.com | ![]() | *** | |
*********.com | ![]() | *** | |
***********.org | ![]() | *** | |
*******.org | ![]() | *,*** | |
********.com | ![]() | *,*** | |
*****.******.com | ![]() | *,*** |
FAQ