Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jainil Borisagar

#31751of 53,635
8.1Total CVSS
Vulnerabilities · 1
PT-2025-39845
8.1
2025-09-29
Tawkto · Tawk.To · CVE-2025-57483
**Name of the Vulnerable Software and Affected Versions** tawk.to chatbox widget version 4 **Description** A reflected cross-site scripting (XSS) issue exists in tawk.to chatbox widget version 4. This allows attackers to execute arbitrary Javascript in the context of a user’s browser by injecting a crafted payload into a vulnerable parameter. The attack vector involves manipulating input to achieve this execution. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.