Description
A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not escaped upon serialization according to the HTML standard.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **>= 6.0.0, < 6.7.3 < 5.10.9** Patched version(s): **6.7.3 5.10.9**
References
Could your website be exposed too?
SmartScanner can check your website for TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes and gives you actionable findings to investigate.
Start a free scanRelated Issues
- rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters - CVE-2023-26491
- Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace] - CVE-2025-27793
- ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor - CVE-2023-37905
- Jodit Editor vulnerable to cross-site scripting - CVE-2023-42399


