CVE-2018-14040

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.


We have discovered 1,222,580 live websites that are affected by CVE-2018-14040.

Test my site




Affected Software

Product  Bootstrap
Category UI Frameworks
Vulnerable Domains1,222,580 live websites (55.92% of Bootstrap install base)
Vulnerable Versions
  • from 0 before 4.1.2
Vulnerable Versions Count246 versions ( 49.00% of all versions)



Details

  • Published - Jul 13, 2018
  • Updated - Aug 5, 2024

CVE-2018-14040 usage by Country

United States536,925 websites



Germany91,167 websites
France67,523 websites
Cyprus44,490 websites
Netherlands44,223 websites
GB35,678 websites
Russia30,983 websites
Japan27,581 websites
Poland24,340 websites
Brazil22,185 websites

CVE-2018-14040 usage by TLD

.com555,792 websites
.org58,576 websites
.de43,732 websites
.net38,093 websites
.nl31,424 websites
.co.uk30,445 websites
.ru27,244 websites
.com.br26,355 websites
.fr24,911 websites
.pl21,543 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-14040

Top websites that are affected by CVE-2018-14040. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.****.br Brazil**
********.com United States***
******.com United States***
**.com Singapore***
*********.com Canada***
*********.com United States***
***********.org United States***
*******.org United States*,***
********.com United States*,***
*****.******.com United States*,***
See full domain list

FAQ

A total of 1,222,580 websites have been identified as vulnerable to CVE-2018-14040, discovered through global website indexing conducted by WebTechSurvey.
Bootstrap is susceptible to CVE-2018-14040 vulnerability.
Bootstrap versions before 4.1.2 are vulnerable to CVE-2018-14040.
Version 4.1.2 of Bootstrap addresses the CVE-2018-14040 security vulnerability.

References