Search CVE reports


Toggle filters

1 – 10 of 18 results


CVE-2024-38357

Medium priority
Vulnerable

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed...

2 affected packages

roundcube, tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Vulnerable Vulnerable Not affected Not affected
tinymce Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-38356

Medium priority
Vulnerable

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing...

2 affected packages

roundcube, tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Vulnerable Vulnerable Not affected Not affected
tinymce Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-29881

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-29203

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-21911

Medium priority
Needs evaluation

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-21910

Medium priority
Needs evaluation

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2024-21908

Medium priority
Needs evaluation

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-48219

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-45819

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE's unfiltered notification system, which is used in...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-45818

Medium priority
Needs evaluation

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-crafted HTML snippet passes the XSS sanitisation...

1 affected package

tinymce

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tinymce Not in release Not in release Needs evaluation Needs evaluation
Show less packages