CVE-2024-21911: Tiny Tinymce

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.

Affected products

  • Tiny Tinymce: before 5.6.0 (fixed in 5.6.0)

Published 2024-01-03. Last modified 2026-07-14.