CVE Tools

Tiny

2 CVEs tracked since 2020. Since Aug 2020, none of them reached CISA KEV.

Tiny CVEs per month

Aug 2020 to Aug 2020. Point at a month, or focus the strip and use the arrow keys.
Tiny CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0820

Products

The products that kept showing up in Tiny's monthly top three, with their CVEs summed over those months.

  1. Tinymce21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Tiny.

  1. CVE-2026-47762TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments8.7
  2. CVE-2026-47761TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection8.7
  3. CVE-2026-47759TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes8.7
  4. CVE-2026-47760TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs8.7
  5. CVE-2025-30091In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-c...—
  6. CVE-2024-29881TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements4.3
  7. CVE-2024-29203TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes4.3
  8. CVE-2024-24701WordPress Setka Editor Plugin <= 2.1.20 is vulnerable to Cross Site Request Forgery (CSRF)4.3
  9. CVE-2024-21911Cross-site scripting vulnerability in TinyMCE6.1
  10. CVE-2024-21910Cross-site scripting vulnerability in TinyMCE plugins6.1
  11. CVE-2024-21908Cross-site scripting vulnerability in TinyMCE6.1
  12. CVE-2023-48219Special characters in unescaped text nodes can trigger mXSS in TinyMCE6.1
  13. CVE-2023-45818Cross-site Scripting vulnerability in TinyMCE undo/redo, getContent API, resetContent API, and Autosave plugin6.1
  14. CVE-2023-45819Cross-site Scripting vulnerability in TinyMCE notificationManager.open API6.1
  15. CVE-2022-23494Cross-site scripting vulnerability in TinyMCE alerts5.4

The record

Peak rank
#189 in Aug 2020
Busiest month shown
Aug 2020, 2 CVEs
Months with a KEV entry
0 since Aug 2020
Monthly snapshots
1 since 2020
Tiny's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store