Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tinymce MEDIUM 5.4
CVE-2026-47759

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attribu…

Fix: 5.11.1 / 7.9.3+
Fix from $1,600 2026-05-28
Tinymce MEDIUM 5.4
CVE-2026-47760

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope …

Fix: 7.1.0+
Fix from $1,600 2026-05-28
Tinymce MEDIUM 5.4
CVE-2026-47761

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can…

Fix: 5.11.1 / 7.9.3+
Fix from $1,600 2026-05-28
Tinymce MEDIUM 5.4
CVE-2026-47762

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments.…

Fix: 5.11.1 / 7.9.3+
Fix from $1,600 2026-05-28
Tinymce MEDIUM 6.1
CVE-2024-29881

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inser…

Fix: 6.8.1 / 7.0.0+
Fix from $1,600 2024-03-26
Tinymce MEDIUM 6.1
CVE-2024-29203

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allo…

Fix: 6.8.1 / 7.0.0+
Fix from $1,600 2024-03-26
Setka Workflow HIGH 8.8
CVE-2024-24701

Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects …

Fix: after 2.1.20
Fix from $1,950 2024-02-29
Tinymce MEDIUM 6.1
CVE-2024-21910

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted im…

Fix: 5.10.0+
Fix from $1,600 2024-01-03
Tinymce MEDIUM 6.1
CVE-2024-21911

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafte…

Fix: 5.6.0+
Fix from $1,600 2024-01-03
Tinymce MEDIUM 6.1
CVE-2024-21908

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafte…

Fix: 5.9.0+
Fix from $1,600 2024-01-03
Tinymce MEDIUM 6.1
CVE-2023-48219

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functiona…

Fix: 5.10.9 / 6.7.3+
Fix from $1,600 2023-11-15
Tinymce MEDIUM 6.1
CVE-2023-45819

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vuln…

Fix: 5.10.8 / 6.7.1+
Fix from $1,600 2023-10-19
Tinymce MEDIUM 6.1
CVE-2023-45818

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo funct…

Fix: 5.10.8 / 6.7.1+
Fix from $1,600 2023-10-19
Tinymce MEDIUM 6.1
CVE-2022-23494

tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dia…

Fix: 5.10.7 / 6.3.1+
Fix from $1,600 2022-12-08
Plupload HIGH 8.8
CVE-2021-23562

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a u…

Fix: 2.3.9+
Fix from $1,950 2021-12-03
Tinymce MEDIUM 6.1
CVE-2020-12648

A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in cla…

Fix: 4.9.11 / 5.4.1+
Fix from $1,600 2020-08-14
Tinymce MEDIUM 6.1
CVE-2020-17480

TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs …

Fix: 4.9.7 / 5.1.4+
Fix from $1,600 2020-08-10
Tinybrowser CRITICAL 9.8
CVE-2011-4908EPSS 56%

TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

Fix: 1.5.13+
Fix from $2,300 2020-02-12
Tinybrowser CRITICAL 9.8
CVE-2011-4906EPSS 10%

Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

Fix: 1.5.13+
Fix from $2,300 2020-02-12
Tinymce MEDIUM 6.1
CVE-2019-1010091

tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution.…

Fix: 4.9.10 / 5.2.2+
Fix from $1,600 2019-07-17