Tawk provides a live-chat and customer-engagement platform embedded in client websites, and its vulnerability footprint centers on the tawk.to service and related live-chat components with a durable signal around web-application input-handling and access-control weaknesses including cross-site scripting, cross-site request forgery, and missing authorization. The concentration of these classes reflects the exposure inherent to a browser-hosted chat widget integrated across many third-party sites. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tawk over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24914HIGH The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenti | Dec 6, 2021 | 8.0 | 26 | NO | NO |
CVE-2025-45960MEDIUM Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input w | Jul 25, 2025 | 6.1 | 23 | NO | NO |
CVE-2024-57026MEDIUM TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution. | Feb 24, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tawk.
Media articles that mention a CVE ID that affects a product developed by Tawk — matched by CVE ID, not by vendor name.