VendorsTinytinymceall versions
Vulnerabilities

Tiny TinyMCE

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2026-47759
TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
Published 2026-05-28 · Analyzed
8.7EPSS 0.003
CVE-2026-47762
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
Published 2026-05-28 · Analyzed
8.7EPSS 0.003
CVE-2026-47761
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
Published 2026-05-28 · Analyzed
8.7EPSS 0.003
CVE-2026-47760
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
Published 2026-05-28 · Analyzed
8.7EPSS 0.002
CVE-2019-1010091
tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.
Published 2019-07-17 · Modified
6.1EPSS 0.019
CVE-2020-12648
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
Published 2020-08-14 · Modified
6.1EPSS 0.018
CVE-2020-17480
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Published 2020-08-10 · Modified
6.1EPSS 0.012
CVE-2024-21911
Cross-site scripting vulnerability in TinyMCE
Published 2024-01-03 · Modified
6.1EPSS 0.012
CVE-2024-21908
Cross-site scripting vulnerability in TinyMCE
Published 2024-01-03 · Modified
6.1EPSS 0.011
CVE-2022-23494
Cross-site scripting vulnerability in TinyMCE alerts
Published 2022-12-08 · Modified
6.1EPSS 0.010
CVE-2024-21910
Cross-site scripting vulnerability in TinyMCE plugins
Published 2024-01-03 · Modified
6.1EPSS 0.010
CVE-2023-48219
Special characters in unescaped text nodes can trigger mXSS in TinyMCE
Published 2023-11-15 · Modified
6.1EPSS 0.007
CVE-2024-29203
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes
Published 2024-03-26 · Analyzed
6.1EPSS 0.007
CVE-2024-29881
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements
Published 2024-03-26 · Analyzed
6.1EPSS 0.007
CVE-2023-45818
Cross-site Scripting vulnerability in TinyMCE undo/redo, getContent API, resetContent API, and Autosave plugin
Published 2023-10-19 · Modified
6.1EPSS 0.006
CVE-2023-45819
Cross-site Scripting vulnerability in TinyMCE notificationManager.open API
Published 2023-10-19 · Modified
6.1EPSS 0.006