Medium severity6.1NVD Advisory· Published Sep 30, 2020· Updated Jun 17, 2026
CVE-2019-20921
CVE-2019-20921
Description
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bootstrap-selectnpm | < 1.13.6 | 1.13.6 |
bootstrap-selectNuGet | < 1.13.6 | 1.13.6 |
Affected products
4- cpe:2.3:a:snapappointments:bootstrap-select:*:*:*:*:*:node.js:*:*Range: <1.13.6
- bootstrap-select/bootstrap-selectdescription
- ghsa-coords2 versions
< 1.13.6+ 1 more
- (no CPE)range: < 1.13.6
- (no CPE)range: < 1.13.6
Patches
Vulnerability mechanics
References
8- github.com/snapappointments/bootstrap-select/issues/2199nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-7c82-mp33-r854ghsaADVISORY
- github.com/advisories/GHSA-9r7h-6639-v5mwnvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2019-20921ghsaADVISORY
- snyk.io/vuln/SNYK-JS-BOOTSTRAPSELECT-570457nvdThird Party AdvisoryWEB
- www.npmjs.com/advisories/1522nvdThird Party Advisory
- github.com/snapappointments/bootstrap-select/commit/ab6e068748040cf3cda5859f6349b382402b8767ghsaWEB
- issues.jtl-software.de/issues/SHOP-7964nvdWEB
News mentions
0No linked articles in our index yet.