CVE-2024-29881
- EPSS 3.99%
- Veröffentlicht 26.03.2024 14:15:09
- Zuletzt bearbeitet 02.09.2025 16:17:16
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could pot...
CVE-2024-29203
- EPSS 1.6%
- Veröffentlicht 26.03.2024 14:15:08
- Zuletzt bearbeitet 02.09.2025 16:20:29
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor. These `ifr...
CVE-2024-21910
- EPSS 1.21%
- Veröffentlicht 03.01.2024 16:15:09
- Zuletzt bearbeitet 18.06.2025 16:15:26
TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's brow...
CVE-2024-21911
- EPSS 0.82%
- Veröffentlicht 03.01.2024 16:15:09
- Zuletzt bearbeitet 11.06.2025 17:15:40
TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
CVE-2024-21908
- EPSS 0.37%
- Veröffentlicht 03.01.2024 16:15:08
- Zuletzt bearbeitet 17.04.2025 19:15:58
TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
CVE-2023-48219
- EPSS 1.98%
- Veröffentlicht 15.11.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:14
TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not escaped upon serializatio...
CVE-2023-45819
- EPSS 2.84%
- Veröffentlicht 19.10.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 08:27:25
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE's unfiltered notification system, which is used in error handling. The con...
CVE-2023-45818
- EPSS 1.28%
- Veröffentlicht 19.10.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:27:25
TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-crafted HTML snippet passes the XSS sanitisation layer, it is manipulated ...
CVE-2022-23494
- EPSS 2.79%
- Veröffentlicht 08.12.2022 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:40
tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confi...
CVE-2020-12648
- EPSS 0.06%
- Veröffentlicht 14.08.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:59
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.