GHSA-9hcv-j9pv-qmph
MODERATECVE-2024-38356A [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) vulnerability was discovered in TinyMCE’s content extraction code. When using the noneditableregexp option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor.
- Affected
- <= 4.0.0
- Fixed in
- 4.1.0
- Weakness
- CWE-79
- Published
- 2024-06-19
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference