TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes
- Severity:
- Medium
Description
A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not escaped upon serialization according to the HTML standard.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **>= 6.0.0, < 6.7.3 < 5.10.9** Patched version(s): **6.7.3 5.10.9**
References
Related Issues
- rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters - CVE-2023-26491
- Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace] - CVE-2025-27793
- ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor - CVE-2023-37905
- Jodit Editor vulnerable to cross-site scripting - CVE-2023-42399
You might also like:
- Tags:
- npm
- tinymce
Anything's wrong? Let us know Last updated on November 15, 2023


