Tinymce

Vendor:

First CVE: Jul 17, 2019 · Active for 7 years

16
Total CVEs
More Total CVEs than 92% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tinymce over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2019
7 years ago
Most Recent CVE
May 28, 2026
57 days ago

CVE Severity & Scoring

Tinymce16 CVEs
All CVEs352,231 CVEs
Medium
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required16 (100.0%)
Privileges Required
Low4 (25.0%)
High0 (0.0%)
None12 (75.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass san
May 28, 20265.425NONO
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via c
May 28, 20265.425NONO
TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A cr
May 28, 20265.425NONO
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-sr
May 28, 20265.425NONO
TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resultin
Jan 3, 20246.121NONO
TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resultin
Jan 3, 20246.121NONO
TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-craf
Oct 19, 20236.121NONO
tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media elemen
Jul 17, 20196.121NONO
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be
Mar 26, 20246.120NONO
TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would res
Jan 3, 20246.120NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Tinymce

Top CWEs

Versions

No cataloged versions.