Skip to main content

Vendor archive

tiny CVEs

Beta · best-effort

21 CVEs tagged to vendor tiny2 Critical, 5 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2026-47762

Published May 28, 2026

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sa…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-47761

Published May 28, 2026

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-47760

Published May 28, 2026

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A c…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47759

Published May 28, 2026

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-s…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-29881

Published Mar 26, 2024

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could b…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29203

Published Mar 26, 2024

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24701

Published Feb 29, 2024

Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for bea…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-21911

Published Jan 3, 2024

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulti…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2024-21910

Published Jan 3, 2024

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would re…

CVSS 6.1 · Medium
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2024-21908

Published Jan 3, 2024

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulti…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2023-48219

Published Nov 15, 2023

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45819

Published Oct 19, 2023

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE's u…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45818

Published Oct 19, 2023

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-cra…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23494

Published Dec 8, 2022

tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malici…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23562

Published Dec 3, 2021

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of fil…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12648

Published Aug 14, 2020

A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-17480

Published Aug 10, 2020

TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the edi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4908

Published Feb 12, 2020

TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4906

Published Feb 12, 2020

Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-1010091

Published Jul 17, 2019

tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media eleme…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1