CVE-2025-1647

EUVD-2025-15170
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.6 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 22.28%
Debian logo
Debian Releases
Debian Product
Codename
twitter-bootstrap3
bookworm
no-dsa
forky
3.4.1+dfsg-7
fixed
sid
3.4.1+dfsg-7
fixed
trixie
3.4.1+dfsg-6
fixed
twitter-bootstrap4
bookworm
4.6.1+dfsg1-4+deb12u1
fixed
forky
4.6.2+dfsg-3
fixed
sid
4.6.2+dfsg-3
fixed
trixie
4.6.2+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
twitter-bootstrap3
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
pki-base
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed
pki-base-java
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed
pki-ca
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed
pki-core-debuginfo
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed
pki-javadoc
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed
pki-kra
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed
pki-server
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed
pki-symkey
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed
pki-tools
Amazon Linux 2
0:10.5.18-27.amzn2.0.3
fixed