TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
- Severity:
- Medium
Description
A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the noneditable_regexp option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **>= 7.0.0, < 7.2.0 >= 6.0.0, < 6.8.4 < 5.11.0** Patched version(s): **7.2.0 6.8.4 5.11.0**
References
Related Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements - CVE-2024-38357
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes - CVE-2024-29203
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs - CVE-2026-47760
You might also like:
- Tags:
- npm
- tinymce
Anything's wrong? Let us know Last updated on August 04, 2024


