Medium severity6.1NVD Advisory· Published Jul 25, 2025· Updated Jul 5, 2026
CVE-2025-45960
CVE-2025-45960
Description
Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- tawk.to/Live Chatdescription
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.