A vulnerability has been identified in Bootstrap that exposes users to Cross-Site Scripting (XSS) attacks. The issue is present in the carousel component, where the data-slide and data-slide-to attributes can be exploited through the href attribute of an <a> tag due to inadequate sanitization. This vulnerability could potentially enable attackers to execute arbitrary JavaScript within the victim's browser.
We have discovered 882,349 live websites that are affected by CVE-2024-6484.
Product | ![]() |
Category | UI Frameworks |
Vulnerable Domains | 882,349 live websites (40.36% of Bootstrap install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 52 versions ( 10.36% of all versions) |
![]() | 381,664 websites |
![]() | 63,288 websites |
![]() | 46,648 websites |
![]() | 41,408 websites |
![]() | 33,143 websites |
![]() | 24,880 websites |
![]() | 21,738 websites |
![]() | 21,487 websites |
![]() | 18,114 websites |
![]() | 17,533 websites |
.com | 403,468 websites |
.org | 41,424 websites |
.de | 29,744 websites |
.net | 28,276 websites |
.co.uk | 21,876 websites |
.nl | 20,972 websites |
.com.br | 20,046 websites |
.ru | 18,987 websites |
.fr | 17,566 websites |
.pl | 15,728 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *** | |
******.com | ![]() | *** | |
**.com | ![]() | *** | |
*********.com | ![]() | *** | |
*******.org | ![]() | *,*** | |
********.com | ![]() | *,*** | |
*****.******.com | ![]() | *,*** | |
***.org | ![]() | *,*** | |
****.org | ![]() | *,*** | |
************.com | ![]() | *,*** |
FAQ