nuget package reportIs TinyMCE safe ? 15 known vulnerabilities, worst severity HIGH.
// reach 0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
// ai model usage Tracked for PyPI packages. HuggingFace models declare Python dependencies, so nuget packages are not covered.
epss chance of exploitation in 30 days, 34th percentile of all CVEs
xyz score CyberXYZ composite out of 10
fig. 01 — GHSA-v98h-vmpc-fpqv, the advisory selected below
// 15 advisories GHSA-v98h-vmpc-fpqv Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. HIGH GHSA-q742-qvgc-gc2f Stored XSS vulnerability via unsanitized data-mce- attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. HIGH GHSA-vg35-5wq7-3x7w Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce- attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. HIGH GHSA-mh5m-5hw4-5c69 TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested <svg> elements can bypass attribute sanitization and execute arbitrary JavaScript. HIGH GHSA-w9jx-4g6g-rp7x A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. MODE GHSA-9hcv-j9pv-qmph A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the noneditableregexp option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor. MODE GHSA-438c-3975-5x3f A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed iframe elements containing malicious code to execute when inserted into the editor. These iframe elements are restricted in their permissions by same-origin browser protections, but could still trigger operations such as downloading of malicious assets. MODE GHSA-5359-pvf2-pw78 A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an object or embed element and that image could potentially contain a XSS payload. MODE GHSA-v626-r774-j7f8 A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not escaped upon serialization according to the HTML standard. If such text nodes contain a special character reserved as an internal marker, they can be combined with other HTML patterns to form malicious snippets. These s MODE GHSA-v65r-p3vv-jjfv A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-crafted HTML snippet passes the XSS sanitisation layer, it is manipulated as a string by internal trimming functions before being stored in the undo stack. If the HTML snippet is restored from the undo stack, the combination of the string manipulation and reparative p MODE Show all 15 advisories // impact Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option.
// patches Patched by validating decoded mce:protected content against configured protect regex rules before restoring. Users should upgrade to the latest patched version.
// workarounds No official workaround available.
// fix To avoid this vulnerability:
Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial long-term support contract).
// acknowledgements Tiny thanks Ivan Babenko for their help identifying this vulnerability.
// cvss v3.1 vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Scope Changed
Confidentiality High
Integrity High
Availability None Checked 2026-10-02 at 23:08 UTC. The most recent advisory here was published 2026-06-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.
Think a verdict here is wrong? Tell us — we respond within 2 business days. Report an issue with this page