CVE-2025-45960: Tawk Tawk.to
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding
Affected products
- Tawk Tawk.to: up to and including 1.6.1
Published 2025-07-25. Last modified 2026-07-05.