VYPR
Medium severity6.1NVD Advisory· Published Jul 25, 2025· Updated Jul 5, 2026

CVE-2025-45960

CVE-2025-45960

Description

Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:tawk:tawk.to:*:*:*:*:*:*:*:*
    Range: <=1.6.1
  • TawkTo/Live Chatcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: =1.6.1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.