CVE-2024-21910

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*

History

28 Nov 2025, 16:15

Type Values Removed Values Added
Summary (en) TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser. (en) TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.

Information

Published : 2024-01-03 16:15

Updated : 2025-11-28 16:15


NVD link : CVE-2024-21910

Mitre link : CVE-2024-21910

CVE.ORG link : CVE-2024-21910


JSON object : View

Products Affected

tiny

  • tinymce
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')