AngularJS is a client-side JavaScript framework that achieved broad adoption across web applications, and its vulnerability profile centers on the framework's core product with weaknesses concentrated in input handling and dynamic code generation. The durable signal is the recurrence of cross-site scripting, prototype pollution, and regular expression denial-of-service conditions—flaws characteristic of a framework operating at the browser-DOM boundary and processing untrusted data during template rendering and object manipulation. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Angularjs over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25844HIGH The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in p | May 1, 2022 | 7.5 | 28 | NO | NO |
CVE-2019-10768HIGH In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload. | Nov 19, 2019 | 7.5 | 25 | NO | NO |
CVE-2022-25869MEDIUM All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure | Jul 15, 2022 | 6.1 | 24 | NO | NO |
CVE-2024-21490HIGH This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vu | Feb 10, 2024 | 7.5 | 23 | NO | NO |
CVE-2021-4231MEDIUM A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site s | May 26, 2022 | 5.4 | 21 | NO | NO |
CVE-2019-14863MEDIUM There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along | Jan 2, 2020 | 6.1 | 21 | NO | NO |
CVE-2017-16009MEDIUM ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag- | Jun 4, 2018 | 6.1 | 21 | NO | NO |
CVE-2023-26118MEDIUM Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to the usage of an insecure regular | Mar 30, 2023 | 5.3 | 20 | NO | NO |
CVE-2023-26117MEDIUM Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expressi | Mar 30, 2023 | 5.3 | 20 | NO | NO |
CVE-2023-26116MEDIUM Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure r | Mar 30, 2023 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Angularjs.
Media articles that mention a CVE ID that affects a product developed by Angularjs — matched by CVE ID, not by vendor name.