Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Angularjs

First CVE: Jun 4, 2018Active for: 8 yearsTotal CVEs: 13
18.5
VTI Score
Low

AngularJS is a client-side JavaScript framework that achieved broad adoption across web applications, and its vulnerability profile centers on the framework's core product with weaknesses concentrated in input handling and dynamic code generation. The durable signal is the recurrence of cross-site scripting, prototype pollution, and regular expression denial-of-service conditions—flaws characteristic of a framework operating at the browser-DOM boundary and processing untrusted data during template rendering and object manipulation. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Angularjs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2018
8 years ago
Most Recent CVE
Sep 9, 2024
683 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-25844HIGH
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in p
May 1, 20227.528NONO
CVE-2019-10768HIGH
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
Nov 19, 20197.525NONO
CVE-2022-25869MEDIUM
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure
Jul 15, 20226.124NONO
CVE-2024-21490HIGH
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vu
Feb 10, 20247.523NONO
CVE-2021-4231MEDIUM
A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site s
May 26, 20225.421NONO
CVE-2019-14863MEDIUM
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along
Jan 2, 20206.121NONO
CVE-2017-16009MEDIUM
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-
Jun 4, 20186.121NONO
CVE-2023-26118MEDIUM
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to the usage of an insecure regular
Mar 30, 20235.320NONO
CVE-2023-26117MEDIUM
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expressi
Mar 30, 20235.320NONO
CVE-2023-26116MEDIUM
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure r
Mar 30, 20235.320NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
77%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (46.2%)
Unknown0 (0.0%)
Required7 (53.8%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None11 (84.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Angularjs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Angularjs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Angularjs's Products

View all 5 CNAs →

Top CWEs