Description
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2189 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-w9jx-4g6g-rp7x | TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements |
Ubuntu USN |
USN-8223-1 | Roundcube Webmail vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:04:25.258Z
Reserved: 2024-06-14T14:16:16.464Z
Link: CVE-2024-38357
Updated: 2024-06-20T13:07:59.295Z
Status : Deferred
Published: 2024-06-19T20:15:11.727
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-38357
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:13:59Z
Weaknesses
EUVD
Github GHSA
Ubuntu USN