CVE-2025-57483
29.09.2025, 18:15
A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the vulnerable parameter.
Awaiting analysis
This vulnerability is currently awaiting analysis.