CVE-2024-38356
- EPSS 0.69%
- Veröffentlicht 19.06.2024 20:15:11
- Zuletzt bearbeitet 21.11.2024 09:25:26
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing malicious code were a...
CVE-2024-38357
- EPSS 1.05%
- Veröffentlicht 19.06.2024 20:15:11
- Zuletzt bearbeitet 21.11.2024 09:25:26
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was l...
CVE-2024-29881
- EPSS 3.99%
- Veröffentlicht 26.03.2024 14:15:09
- Zuletzt bearbeitet 02.09.2025 16:17:16
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could pot...
CVE-2024-29203
- EPSS 1.6%
- Veröffentlicht 26.03.2024 14:15:08
- Zuletzt bearbeitet 02.09.2025 16:20:29
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor. These `ifr...
CVE-2012-4230
- EPSS 0.62%
- Veröffentlicht 25.04.2014 14:15:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific ve...
CVE-2011-4825
- EPSS 83.04%
- Veröffentlicht 15.12.2011 03:57:34
- Zuletzt bearbeitet 11.04.2025 00:51:21
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject a...