Tinymce
Vendor:
First CVE: Jul 17, 2019 · Active for 7 years
16
Total CVEs
More Total CVEs than 92% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tinymce over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2019
7 years ago
Most Recent CVE
May 28, 2026
57 days ago
CVE Severity & Scoring
Tinymce16 CVEs
100%
All CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required16 (100.0%)
Privileges Required
Low4 (25.0%)
High0 (0.0%)
None12 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-47762MEDIUM TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass san | May 28, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-47761MEDIUM TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via c | May 28, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-47760MEDIUM TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A cr | May 28, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-47759MEDIUM TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-sr | May 28, 2026 | 5.4 | 25 | NO | NO |
CVE-2024-21911MEDIUM TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resultin | Jan 3, 2024 | 6.1 | 21 | NO | NO |
CVE-2024-21908MEDIUM TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resultin | Jan 3, 2024 | 6.1 | 21 | NO | NO |
CVE-2023-45818MEDIUM TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-craf | Oct 19, 2023 | 6.1 | 21 | NO | NO |
CVE-2019-1010091MEDIUM tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media elemen | Jul 17, 2019 | 6.1 | 21 | NO | NO |
CVE-2024-29881MEDIUM TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be | Mar 26, 2024 | 6.1 | 20 | NO | NO |
CVE-2024-21910MEDIUM TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would res | Jan 3, 2024 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Tinymce
Top CWEs
Versions
No cataloged versions.