TinyMCE is a widely embedded rich-text editor component used across content management systems, web applications, and user-facing platforms, presenting a supply-chain exposure pattern where a single flaw can propagate broadly to downstream integrations. Vulnerabilities affecting the vendor recur through web-layer weakness classes including cross-site scripting, cross-site request forgery, code injection, and improper input validation, reflecting the parser and content-handling complexity inherent to an HTML editor; these issues frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinymce over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4825HIGH Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2 | Dec 15, 2011 | 7.5 | 63 | NO | YES |
CVE-2012-3414MEDIUM Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows | Jul 19, 2013 | 4.3 | 31 | NO | YES |
CVE-2012-4230MEDIUM The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to | Apr 25, 2014 | 4.3 | 19 | NO | NO |
CVE-2012-6112MEDIUM classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before | Jan 27, 2013 | 5.0 | 19 | NO | NO |
CVE-2014-3845MEDIUM Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified user | May 22, 2014 | 6.8 | 18 | NO | NO |
CVE-2013-2204MEDIUM moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) charac | Jul 8, 2013 | 4.3 | 16 | NO | NO |
CVE-2014-3844MEDIUM The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors. NOTE | May 22, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinymce.
Media articles that mention a CVE ID that affects a product developed by Tinymce — matched by CVE ID, not by vendor name.