Search CVE reports


Toggle filters

1 – 10 of 18 results


CVE-2026-22610

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS)...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-66412

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-66035

Medium priority
Needs evaluation

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-4690

Medium priority
Needs evaluation

A regular expression used by AngularJS'  linky https://docs.angularjs.org/api/ngSanitize/filter/linky  filter to detect URLs in input text is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-2336

Medium priority

Some fixes available 5 of 6

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'ngSanitize' module allows attackers to bypass common image source restrictions. This can lead to a form of ...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-0716

Medium priority

Some fixes available 6 of 7

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-54152

Medium priority
Ignored

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-8373

Medium priority

Some fixes available 5 of 6

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-8372

Medium priority

Some fixes available 5 of 6

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-21490

Medium priority

Some fixes available 5 of 7

This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this...

1 affected package

angular.js

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Fixed Fixed Fixed Fixed
Show less packages