bootstrap-table@1.19.1 vulnerabilities

An extended table to integration with some of the most widely used CSS frameworks. (Supports Bootstrap, Semantic UI, Bulma, Material Design, Foundation)

Direct Vulnerabilities

Known vulnerabilities in the bootstrap-table package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

bootstrap-table is an extended table to integration with some of the most widely used CSS frameworks. (Supports Bootstrap, Semantic UI, Bulma, Material Design, Foundation, Vue.js).

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the onCellHtmlData function. If you set the exportOptions in the Bootstrap Table to true, it will allow arbitrary Javascript to execute.

How to fix Cross-site Scripting (XSS)?

Upgrade bootstrap-table to version 1.20.2 or higher.

<1.20.2
  • M
Cross-site Scripting (XSS)

bootstrap-table is an extended table to integration with some of the most widely used CSS frameworks. (Supports Bootstrap, Semantic UI, Bulma, Material Design, Foundation, Vue.js).

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper sanitization of the onCellHtmlData callback method, it is possible to be exploited when exportOptions is set to "true".

How to fix Cross-site Scripting (XSS)?

Upgrade bootstrap-table to version 1.20.2 or higher.

<1.20.2