CVE-2025-57483

HIGH

tawk.to chatbox widget <4 - XSS

Title source: llm

Description

A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the vulnerable parameter.

Exploits (1)

nomisec WRITEUP 1 stars
by Jainil-89 · poc
https://github.com/Jainil-89/CVE

Scores

CVSS v3 8.1
EPSS 0.0003
EPSS Percentile 8.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published Sep 29, 2025
Tracked Since Feb 18, 2026