CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-47762 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

CVSS 8.7 EPSS 0.42% May 28, 2026
NuGetPackagistnpm
CVE-2026-47761 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection

CVSS 8.7 EPSS 0.41% May 28, 2026
NuGetPackagistnpm
CVE-2026-47759 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

CVSS 8.7 EPSS 0.42% May 28, 2026
NuGetPackagistnpm
CVE-2026-47760 HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

CVSS 8.7 EPSS 0.27% May 28, 2026
NuGetPackagistnpm
CVE-2024-38357 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

CVSS 5.3 EPSS 0.53% Jun 19, 2024
NuGetPackagistPyPInpm
CVE-2024-38356 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

CVSS 5.3 EPSS 0.53% Jun 19, 2024
NuGetPackagistPyPInpm
CVE-2024-29881 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

CVSS 6.1 EPSS 0.71% Mar 26, 2024
NuGetPackagistnpm
CVE-2024-29203 MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

CVSS 6.1 EPSS 0.71% Mar 26, 2024
NuGetPackagistnpm
CVE-2023-48219 MEDIUM

Special characters in unescaped text nodes can trigger mXSS in TinyMCE

CVSS 6.1 EPSS 0.71% Nov 15, 2023
NuGetPackagistnpm
CVE-2023-45818 MEDIUM

Cross-site Scripting vulnerability in TinyMCE undo/redo, getContent API, resetContent API, and Autosave plugin

CVSS 6.1 EPSS 0.62% Oct 19, 2023
NuGetPackagistnpm
CVE-2023-45819 MEDIUM

Cross-site Scripting vulnerability in TinyMCE notificationManager.open API

CVSS 6.1 EPSS 0.60% Oct 19, 2023
NuGetPackagistnpm
CVE-2022-23494 MEDIUM

Cross-site scripting vulnerability in TinyMCE alerts

CVSS 6.1 EPSS 0.98% Dec 8, 2022
NuGetPackagistnpm
CVE-2019-1010091 MEDIUM

tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The compo…

CVSS 6.1 EPSS 1.92% Jul 17, 2019
npm
CVE-2014-3845 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authenticatio…

CVSS 6.8 EPSS 0.95% May 22, 2014
CVE-2014-3844 MEDIUM

The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspe…

CVSS 5.0 EPSS 1.78% May 22, 2014
CVE-2012-4230 MEDIUM

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which…

CVSS 4.3 EPSS 1.20% Apr 25, 2014
CVE-2012-3414 MEDIUM

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and o…

CVSS 4.3 EPSS 9.09% Jul 19, 2013
CVE-2013-2204 MEDIUM

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a…

CVSS 4.3 EPSS 2.90% Jul 8, 2013
CVE-2012-6112 MEDIUM

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before…

CVSS 5.0 EPSS 2.29% Jan 27, 2013
CVE-2011-4825 HIGH

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.…

CVSS 7.5 EPSS 39.16% Dec 15, 2011

Showing 1 to 20 CVEs · page 1