Angularjs
This hub aggregates every CVE we track for Angularjs, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM12HIGH2LOW1
Monthly trend
2
0
0
0
0
0
0
1
0
1
0
1
0
0
0
0
0
0
0
0
0
1
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Angularjs.
- CVE-2026-11998AngularJS XSS via SCE resource URL sanitization bypass7.6
- CVE-2025-4690AngularJS 'linky' filter ReDoS4.3
- CVE-2025-2336AngularJS improper sanitization in SVG '<image>' element with 'ngSanitize'4.8
- CVE-2025-0716AngularJS improper sanitization in SVG '<image>' element4.8
- CVE-2024-8373AngularJS improper sanitization in '<source>' element4.8
- CVE-2024-8372AngularJS improper sanitization in 'srcset' attribute4.8
- CVE-2023-26116Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression...5.3
- CVE-2023-26118Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to the usage of an insecure regular expression in th...5.3
- CVE-2023-26117Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting th...5.3
- CVE-2022-25869All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in t...4.2
- CVE-2021-4231Angular Comment cross site scripting3.5
- CVE-2022-25844Regular Expression Denial of Service (ReDoS)5.3
- CVE-2020-7676angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes p...5.4
- CVE-2019-14863There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other truste...6.1
- CVE-2019-10768In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.7.5
Product normalization is registry-driven with AI assist and human review. How it works