CVE-2024-21908: Tiny Tinymce

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.

Affected products

  • Tiny Tinymce: before 5.9.0 (fixed in 5.9.0)

Published 2024-01-03. Last modified 2026-07-14.