Vulnerabilities
Vulnerable Software
Tiny:  >> Tinymce  >> 6.8.2  Security Vulnerabilities
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could potentially contain a XSS payload. This vulnerability is fixed in 6.8.1 and 7.0.0.
CVSS Score
4.3
EPSS Score
0.025
Published
2024-03-26
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor. These `iframe` elements are restricted in their permissions by same-origin browser protections, but could still trigger operations such as downloading of malicious assets. This vulnerability is fixed in 6.8.1.
CVSS Score
4.3
EPSS Score
0.016
Published
2024-03-26


Contact Us

Shodan ® - All rights reserved