CVE-2025-66412

Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.


We have discovered 16,808 live websites that are affected by CVE-2025-66412.

Run a Free Instant Scan




Affected Software

Product  Angular
Category Web Application Frameworks
Vulnerable Domains16,808 live websites (67% of Angular install base)
Vulnerable Versions
  • from 0 through 18.2.14
  • from 19 through 19.2.17
  • from 20 through 20.3.15
  • from 21 through 21.0.2
Vulnerable Versions Count408 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 1, 2025
  • Updated - Dec 2, 2025

Website Distribution by Country

Number of websites using CVE-2025-66412
United States6,877 websites



Germany1,903 websites
Iran782 websites
France613 websites
GB537 websites
Russia528 websites
Brazil477 websites
Italy363 websites
India304 websites
Belgium271 websites

Website Distribution by TLD

Number of websites using CVE-2025-66412
.com5,658 websites
.de1,357 websites
.org542 websites
.co.uk465 websites
.ru437 websites
.fr404 websites
.it358 websites
.com.br339 websites
.be315 websites
.net291 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-66412

Top websites that are affected by CVE-2025-66412. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States***
****.ir Iran*,***
************.com United States*,***
*************.net United States*,***
***.fr France*,***
********.com United States*,***
******.*****.com Luxembourg*,***
***********.***.au Australia*,***
******.ru Russia*,***
*****.com United States*,***
See full domain list

FAQ

CVE-2025-66412 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Angular
A total of 16,808 websites have been identified as vulnerable to CVE-2025-66412, based on global website indexing conducted by WebTechSurvey.
The Angular is affected by the CVE-2025-66412 vulnerability.
Angular versions up to 21.0.2 are vulnerable to CVE-2025-66412.
CVE-2025-66412 is resolved in version 21.0.2 of Angular.