Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data
- Severity:
- Medium
Description
An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).
Recommendation
Update the bootstrap-multiselect package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.0
- Patched version(s): 2.0.0
References
Related Issues
- Fiora chat group avatar is vulnerable to XSS via SVG files - CVE-2025-56515
- Quill is vulnerable to XSS via HTML export feature - CVE-2025-15056
- jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin - CVE-2025-9910
- MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server - CVE-2025-58444
You might also like:
- Tags:
- npm
- bootstrap-multiselect
Anything's wrong? Let us know Last updated on February 26, 2026


