Tiny develops a focused portfolio of widely embedded web-based components and editors, most notably TinyMCE, that serve as foundational building blocks across content-management systems, publishing platforms, and web applications. Although the vendor's product count is narrow, the deep integration of these libraries into downstream applications means that vulnerabilities can propagate across a much larger installed base than raw product metrics suggest. The recurring vulnerability surface concentrates on web-application input-handling and file-management concerns: cross-site scripting flaws, unrestricted file uploads, and cross-site request forgery weaknesses that reflect the attack surface inherent to editor and content-processing components. Vulnerabilities affecting this vendor have a moderate tendency toward serious severity and a moderate tendency to acquire public exploit code. Defenders should track this vendor's releases closely and prioritize patching in internet-exposed or user-supplied-content contexts; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tiny over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4908CRITICAL TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. | Feb 12, 2020 | 9.8 | 78 | NO | YES |
CVE-2011-4906CRITICAL Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution. | Feb 12, 2020 | 9.8 | 45 | NO | YES |
CVE-2021-23562HIGH This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file | Dec 3, 2021 | 8.8 | 28 | NO | NO |
CVE-2026-47762MEDIUM TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass san | May 28, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-47761MEDIUM TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via c | May 28, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-47760MEDIUM TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A cr | May 28, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-47759MEDIUM TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-sr | May 28, 2026 | 5.4 | 25 | NO | NO |
CVE-2019-10012HIGH Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager ( | Mar 25, 2019 | 7.5 | 25 | NO | NO |
CVE-2024-24701HIGH Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beau | Feb 29, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-21911MEDIUM TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resultin | Jan 3, 2024 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tiny.
Media articles that mention a CVE ID that affects a product developed by Tiny — matched by CVE ID, not by vendor name.