Description
A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE’s unfiltered notification system, which is used in error handling.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **< 5.10.8 >= 6.0.0, < 6.7.1** Patched version(s): **5.10.8 6.7.1**
References
Related Issues
- TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin - CVE-2023-45818
- XSS Attack with Express API - CVE-2023-23630
- NASA Open MCT Cross Site Scripting vulnerability - CVE-2023-45885
- TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments - CVE-2026-47762
You might also like:
- Tags:
- npm
- tinymce
Anything's wrong? Let us know Last updated on November 07, 2023


