Google Tag Project maintains the Google Tag Manager product, a widely embedded web-based tag management and analytics platform that sits in the client-side tracking and instrumentation layer of many websites. Its vulnerability exposure centers on web-application input-handling weaknesses, particularly cross-site request forgery and cross-site scripting flaws that are endemic to client-facing tag-injection and script-execution contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Google Tag Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31683MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0 | Mar 31, 2025 | 6.8 | 20 | NO | NO |
CVE-2025-31682MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS).This issue affects Google | Mar 31, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Google Tag Project.
Media articles that mention a CVE ID that affects a product developed by Google Tag Project — matched by CVE ID, not by vendor name.