CVE-2025-8349
Cross-Site Scripting (XSS) stored in Tawk Live Chat
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
14th
Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by uploading a malicious PDF with JavaScript payload through the chatbot. The PDF is stored by the application and subsequently displayed without proper sanitisation when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
| CWE | CWE-79 |
| Vendor | tawk |
| Product | live chat |
| Published | Oct 20, 2025 |
| Last Updated | Mar 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for tawk live chat
Be the first to know when new unknown vulnerabilities affecting tawk live chat are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Tawk / Live Chat
0 ≤ *
References
Credits
José Manuel Jerónimo Rodríguez