Back to search
CVE-2024-21910
Published: Jan 3, 2024
Modified: Nov 28, 2025
PUBLISHED
Description
TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.
| Vendor | Product | Versions |
|---|---|---|
Unknown | TinyMCE | affected 0 - < 5.10.0 |
Weaknesses (CWE)
References
https://github.com/jazzband/django-tinymce/issues/366
issue-tracking
https://github.com/advisories/GHSA-r8hm-w5f7-wj39
third-party-advisory
https://vulncheck.com/advisories/vc-advisory-GHSA-r8hm-w5f7-wj39
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now