VYPR
Medium severity6.1NVD Advisory· Published Jul 25, 2025· Updated Jul 5, 2026

CVE-2025-45960

CVE-2025-45960

Description

Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:tawk:tawk.to:*:*:*:*:*:*:*:*
    Range: <=1.6.1
  • tawk.to/Live Chatdescription
  • TawkTo/Live Chatllm-create
    Range: =1.6.1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.