CVE-2024-21910: Tiny Tinymce
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.
Affected products
- Tiny Tinymce: before 5.10.0 (fixed in 5.10.0)
Published 2024-01-03. Last modified 2026-07-14.