Description
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
Remediation
References
Related Vulnerabilities
axios Improper Authentication Vulnerability (CVE-2026-42041)
WordPress Plugin Flat Preloader Cross-Site Request Forgery (1.5.3)
math.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-1001002)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5321)