PT-2025-30900 · Unknown · Tawk.To Live Chat

Pracharapol

·

Published

2025-07-25

·

Updated

2025-10-14

·

CVE-2025-45960

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions tawk.to Live Chat version 1.6.1
Description A Cross Site Scripting issue exists in tawk.to Live Chat. The web application stores and displays user-supplied input without proper input validation or encoding, potentially allowing a remote attacker to execute arbitrary code.
Recommendations Update tawk.to Live Chat to a version with appropriate input validation and encoding to address this issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-45960

Affected Products

Tawk.To Live Chat