Loading HuntDB...

GHSA-w9jx-4g6g-rp7x

GitHub Security Advisory

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact
A [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor.

### Patches
This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed.

### Fix
To avoid this vulnerability:

* Upgrade to TinyMCE 7.2.0 or higher.
* Upgrade to TinyMCE 6.8.4 or higher for TinyMCE 6.x.
* Upgrade to TinyMCE 5.11.0 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract).

### Acknowledgements
Tiny thanks [Malav Khatri](https://malavkhatri.com/) and another reporter for their help identifying this vulnerability.

### References
* [TinyMCE 6.8.4](https://www.tiny.cloud/docs/tinymce/6/6.8.4-release-notes/#overview)
* [TinyMCE 7.2.0](https://www.tiny.cloud/docs/tinymce/7/7.2-release-notes/#overview)

### For more information
If you have any questions or comments about this advisory:

* Email us at [[email protected]](mailto:[email protected])
* Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues?q=is%3Aissue+is%3Aopen+sort%3Aupdated-desc)

Affected Packages

npm tinymce
Affected versions: 0 (fixed in 5.11.0)
NuGet TinyMCE
Affected versions: 0 (fixed in 5.11.0)
Packagist tinymce/tinymce
Affected versions: 0 (fixed in 5.11.0)
npm tinymce
Affected versions: 6.0.0 (fixed in 6.8.4)
npm tinymce
Affected versions: 7.0.0 (fixed in 7.2.0)
NuGet TinyMCE
Affected versions: 6.0.0 (fixed in 6.8.4)
NuGet TinyMCE
Affected versions: 7.0.0 (fixed in 7.2.0)
Packagist tinymce/tinymce
Affected versions: 6.0.0 (fixed in 6.8.4)
Packagist tinymce/tinymce
Affected versions: 7.0.0 (fixed in 7.2.0)
PyPI django-tinymce
Affected versions: 0 (fixed in 4.1.0)

Related CVEs

Key Information

GHSA ID
GHSA-w9jx-4g6g-rp7x
Published
June 19, 2024 3:07 PM
Last Modified
July 5, 2024 9:37 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
tinymce
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 1, 2025 6:44 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.