Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.
We have discovered 16,808 live websites that are affected by CVE-2025-66412.
| Product | |
| Category | Web Application Frameworks |
| Vulnerable Domains | 16,808 live websites (67% of Angular install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 408 versions ( 97% of all versions) |
| 6,877 websites | |
| 1,903 websites | |
| 782 websites | |
| 613 websites | |
| 537 websites | |
| 528 websites | |
| 477 websites | |
| 363 websites | |
| 304 websites | |
| 271 websites |
| .com | 5,658 websites |
| .de | 1,357 websites |
| .org | 542 websites |
| .co.uk | 465 websites |
| .ru | 437 websites |
| .fr | 404 websites |
| .it | 358 websites |
| .com.br | 339 websites |
| .be | 315 websites |
| .net | 291 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.org | *** | ||
| ****.ir | *,*** | ||
| ************.com | *,*** | ||
| *************.net | *,*** | ||
| ***.fr | *,*** | ||
| ********.com | *,*** | ||
| ******.*****.com | *,*** | ||
| ***********.***.au | *,*** | ||
| ******.ru | *,*** | ||
| *****.com | *,*** |
FAQ