CVE Tools

Angularjs

15 CVEs tracked since 2026. Since Jun 2026, none of them reached CISA KEV.

Angularjs CVEs per month

Jun 2026 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Angularjs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-06150

Products

The products that kept showing up in Angularjs's monthly top three, with their CVEs summed over those months.

  1. Angularjs151 month

Latest CVEs

The 12 most recently published vulnerabilities affecting Angularjs.

  1. CVE-2024-8373AngularJS improper sanitization in '<source>' element4.8
  2. CVE-2024-8372AngularJS improper sanitization in 'srcset' attribute4.8
  3. CVE-2024-21490This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super...7.5
  4. CVE-2023-26116Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression...5.3
  5. CVE-2023-26118Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to the usage of an insecure regular expression in th...5.3
  6. CVE-2023-26117Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting th...5.3
  7. CVE-2022-25869All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in t...4.2
  8. CVE-2021-4231Angular Comment cross site scripting3.5
  9. CVE-2022-25844Regular Expression Denial of Service (ReDoS)5.3
  10. CVE-2020-7676angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes p...5.4
  11. CVE-2019-14863There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other truste...6.1
  12. CVE-2019-10768In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.7.5

The record

Peak rank
#69 in Jun 2026
Busiest month shown
Jun 2026, 15 CVEs
Months with a KEV entry
0 since Jun 2026
Monthly snapshots
1 since 2026
Angularjs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store