🔐 CVE Alert

CVE-2025-8349

UNKNOWN 0.0

Cross-Site Scripting (XSS) stored in Tawk Live Chat

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
14th

Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by uploading a malicious PDF with JavaScript payload through the chatbot. The PDF is stored by the application and subsequently displayed without proper sanitisation when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

CWE CWE-79
Vendor tawk
Product live chat
Published Oct 20, 2025
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for tawk live chat

Be the first to know when new unknown vulnerabilities affecting tawk live chat are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Tawk / Live Chat
0 ≤ *

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-stored-tawk-live-chat

Credits

José Manuel Jerónimo Rodríguez