CVE Tools

Tinymce

6 CVEs tracked since 2011. Since Dec 2011, none of them reached CISA KEV.

Tinymce CVEs per month

Dec 2011 to May 2014. Point at a month, or focus the strip and use the arrow keys.
Tinymce CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2011-1210
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-08null or fewer
2012-09null or fewer
2012-10null or fewer
2012-11null or fewer
2012-12null or fewer
2013-0110
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-0720
2013-08null or fewer
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-0520

Products

The products that kept showing up in Tinymce's monthly top three, with their CVEs summed over those months.

  1. Color Picker21 month
  2. Image Manager11 month
  3. Media11 month
  4. Spellchecker PHP11 month
  5. Tinymce11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Tinymce.

  1. CVE-2026-47762TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments8.7
  2. CVE-2026-47761TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection8.7
  3. CVE-2026-47759TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes8.7
  4. CVE-2026-47760TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs8.7
  5. CVE-2024-38357TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements6.1
  6. CVE-2024-38356TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option6.1
  7. CVE-2024-29881TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements4.3
  8. CVE-2024-29203TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes4.3
  9. CVE-2023-48219Special characters in unescaped text nodes can trigger mXSS in TinyMCE6.1
  10. CVE-2023-45818Cross-site Scripting vulnerability in TinyMCE undo/redo, getContent API, resetContent API, and Autosave plugin6.1
  11. CVE-2023-45819Cross-site Scripting vulnerability in TinyMCE notificationManager.open API6.1
  12. CVE-2022-23494Cross-site scripting vulnerability in TinyMCE alerts5.4
  13. CVE-2019-1010091tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vec...6.1
  14. CVE-2014-3845Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests th...6.8
  15. CVE-2014-3844The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors. NOTE: some of these d...5.0

The record

Peak rank
#56 in Jul 2013
Busiest month shown
Jul 2013, 2 CVEs
Months with a KEV entry
0 since Dec 2011
Monthly snapshots
4 since 2011
Tinymce's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store