Vulnerabilities/

Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-5vm8-hhgr-jcjp

Severity:
Medium

Description

A cross-site scripting (XSS) vulnerability was discovered in the URL sanitization logic of the core parser for form elements. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor using the clipboard or APIs, and then submitting the form.

Recommendation

Update the tinymce package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tinymce
Anything's wrong? Let us know Last updated on January 09, 2023