CVE-2024-21908Medium· 6.1▾ SunlitTinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's bro…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
tinymce < 5.9.0Upgrade past the affected range:
tinymce 5.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-21911Medium· 6.1TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability
CVE-2024-38357Medium· 6.1TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
CVE-2024-21910Medium· 6.1Cross-site scripting vulnerability in TinyMCE plugins
CVE-2024-38356Medium· 6.1TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library