OsVault/npm/tinymce
npm

tinymce

19 known vulnerabilities · 0 critical · 0 high

CVE-2020-12648MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Aug 11, 2020
CVE-2024-21908MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Oct 22, 2021
CVE-2024-29203MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

Published Mar 26, 2024
CVE-2024-29881MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

Published Mar 26, 2024
CVE-2024-38357MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

Published Jun 19, 2024
CVE-2024-21910MEDIUM

Cross-site scripting vulnerability in TinyMCE plugins

Published Nov 2, 2021
CVE-2024-21911MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Jan 6, 2021
CVE-2023-45818MEDIUM

TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin

Published Oct 19, 2023
CVE-2023-45819MEDIUM

TinyMCE XSS vulnerability in notificationManager.open API

Published Oct 19, 2023
CVE-2022-23494MEDIUM

Cross-site scripting vulnerability in TinyMCE alerts

Published Dec 8, 2022
CVE-2020-17480MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Jan 30, 2020
CVE-2023-48219MEDIUM

TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes

Published Nov 15, 2023
CVE-2019-1010091MEDIUM

XSS in TinyMCE

Published May 11, 2020
GHSA-mh5m-5hw4-5c69

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

Published Jun 5, 2026
GHSA-q742-qvgc-gc2f

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

Published Jun 5, 2026
GHSA-vg35-5wq7-3x7w

TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection

Published Jun 5, 2026
CVE-2024-38356MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

Published Jun 19, 2024
GHSA-v98h-vmpc-fpqv

TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

Published Jun 5, 2026
MAL-2023-921

Malicious code in uploadcare-tinymce (npm)

Published Apr 12, 2023
Check your entire dependency tree at onceRun dependency scan →