Description
All versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.
NPM package angular is deprecated. Those who want to receive security updates should use the actively maintained package @angular/core.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.8.3
References
Could your website be exposed too?
SmartScanner can check your website for Angular (deprecated package) Cross-site Scripting and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Angular's deprecated package has a Cross-Site Scripting issue - CVE-2026-11998
- AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes - CVE-2019-14863
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - CVE-2022-31175
- Toast UI Grid vulnerable to Cross-site Scripting - CVE-2022-23458


