Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-47760 |
|
Cross-Site Scripting (XSS) in tinymce (CVE-2026-47760)
cross-site scripting in tinymce (CVE-2026-47760). Confidential information can be exposed externally. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2024-21910 |
|
Vulnerability in django-tinymce (CVE-2024-21910)
vulnerability in django-tinymce (CVE-2024-21910). Risk of unauthorized operations or information disclosure. Exploitable via ``image``. Mitigation: upgrade to `3.4.0` or later.
|
| CVE-2024-21911 |
|
Cross-Site Scripting (XSS) in tinymce (CVE-2024-21911)
cross-site scripting in tinymce (CVE-2024-21911). Risk of unauthorized operations or information disclosure. Exploitable via ``iframe``. Mitigation: upgrade to `5.6.0` or later.
|
| CVE-2024-21908 |
|
Cross-Site Scripting (XSS) in tinymce (CVE-2024-21908)
cross-site scripting in tinymce (CVE-2024-21908). Risk of unauthorized operations or information disclosure. Exploitable via ``BeforeSetContent``. Mitigation: upgrade to `5.9.0` or later.
|