← Vulnerability feed

Vulnerability record · CVE-2022-25869 · published 15 July 2022

CVE-2022-25869: Angularjs cross-site scripting vulnerability

Angularjs · Angularjs

All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

6.1 CVSS 3.1 Medium EPSS 7.3% · top 5.9% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
7.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25869 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2022-25844Angularjs inefficient regular expression (redos) vulnerabilityThe package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possib…EPSS 4.9%7.5CVE-2019-10768Angularjs prototype pollution vulnerabilityIn AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` paylo…EPSS 2.0%6.1CVE-2019-14863Angularjs cross-site scripting vulnerabilityThere is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application de…EPSS 1.2%5.4CVE-2021-4231Angular cross-site scripting vulnerabilityA vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The man…EPSS 1.2%5.4CVE-2020-7676Angularjs cross-site scripting vulnerabilityangular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping …EPSS 1.9%5.3CVE-2023-26116Angularjs inefficient regular expression (redos) vulnerabilityVersions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function du…EPSS 1.7%5.3CVE-2023-26117Angularjs inefficient regular expression (redos) vulnerabilityVersions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage …EPSS 1.7%5.3CVE-2023-26118Angularjs inefficient regular expression (redos) vulnerabilityVersions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to t…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2022-25869), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.