Description
A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **>= 7.0.0, < 7.2.0 >= 6.0.0, < 6.8.4 < 5.11.0** Patched version(s): **7.2.0 6.8.4 5.11.0**
References
Could your website be exposed too?
SmartScanner can check your website for TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements and gives you actionable findings to investigate.
Start a free scanRelated Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option - CVE-2024-38356
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs - CVE-2026-47760
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes - CVE-2024-29203


