CVE-2024-6484

XSS in Bootstrap carousel component

A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an <a> tag due to inadequate sanitization. This vulnerability could potentially enable attackers to execute arbitrary JavaScript within the victim's browser.


We have discovered 882,349 live websites that are affected by CVE-2024-6484.

Test my site




Affected Software

Product  Bootstrap
Category UI Frameworks
Vulnerable Domains882,349 live websites (40.36% of Bootstrap install base)
Vulnerable Versions
  • from 3.2 through 3.4.1
Vulnerable Versions Count52 versions ( 10.36% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 11, 2024
  • Updated - Jan 23, 2025

Credits

  • K (finder)

CVE-2024-6484 usage by Country

United States381,664 websites



Germany63,288 websites
France46,648 websites
Cyprus41,408 websites
Netherlands33,143 websites
GB24,880 websites
Japan21,738 websites
Russia21,487 websites
Poland18,114 websites
Brazil17,533 websites

CVE-2024-6484 usage by TLD

.com403,468 websites
.org41,424 websites
.de29,744 websites
.net28,276 websites
.co.uk21,876 websites
.nl20,972 websites
.com.br20,046 websites
.ru18,987 websites
.fr17,566 websites
.pl15,728 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-6484

Top websites that are affected by CVE-2024-6484. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States***
******.com United States***
**.com Singapore***
*********.com United States***
*******.org United States*,***
********.com United States*,***
*****.******.com United States*,***
***.org France*,***
****.org United States*,***
************.com United States*,***
See full domain list

FAQ

CVE-2024-6484 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Bootstrap
A total of 882,349 websites have been identified as vulnerable to CVE-2024-6484, discovered through global website indexing conducted by WebTechSurvey.
Bootstrap is susceptible to CVE-2024-6484 vulnerability.
Bootstrap versions before, and including, 3.4.1 are vulnerable to CVE-2024-6484.