Back to search
CVE-2024-21908
Published: Jan 3, 2024
Modified: Nov 28, 2025
PUBLISHED
Description
TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
| Vendor | Product | Versions |
|---|---|---|
Unknown | TinyMCE | affected 0 - < 5.9.0 |
Weaknesses (CWE)
References
https://github.com/advisories/GHSA-5h9g-x5rv-25wg
third-party-advisory
https://vulncheck.com/advisories/vc-advisory-GHSA-5h9g-x5rv-25wg
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now