Vulnerabilities/

TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes

Severity:
Medium

Description

A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not escaped upon serialization according to the HTML standard.

Recommendation

Update the tinymce package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tinymce
Anything's wrong? Let us know Last updated on November 15, 2023