CVE-2023-46998: Bootboxjs Bootbox

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.

Affected products

  • Bootboxjs Bootbox: from 3.2.0, up to and including 6.0.0

Published 2023-11-07. Last modified 2026-06-17.