Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22733 | Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding |
| Link | Providers |
|---|---|
| http://tawkto.com |
|
| https://github.com/pracharapol/CVE-2025-45960 |
|
Tue, 14 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tawk
Tawk tawk.to |
|
| CPEs | cpe:2.3:a:tawk:tawk.to:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tawk
Tawk tawk.to |
Fri, 25 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 25 Jul 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-25T20:26:42.995Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-45960
Updated: 2025-07-25T20:26:36.845Z
Status : Analyzed
Published: 2025-07-25T17:15:32.670
Modified: 2025-10-14T14:06:11.450
Link: CVE-2025-45960
No data.
OpenCVE Enrichment
No data.
EUVD