CVE-2024-21910

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*

History

28 Nov 2025, 16:15

Type Values Removed Values Added
Summary (en) TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser. (en) TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://github.com/advisories/GHSA-r8hm-w5f7-wj39 - Exploit, Third Party Advisory () https://github.com/advisories/GHSA-r8hm-w5f7-wj39 - Exploit, Third Party Advisory
References () https://github.com/jazzband/django-tinymce/issues/366 - Issue Tracking, Third Party Advisory () https://github.com/jazzband/django-tinymce/issues/366 - Issue Tracking, Third Party Advisory
References () https://github.com/jazzband/django-tinymce/releases/tag/3.4.0 - Release Notes () https://github.com/jazzband/django-tinymce/releases/tag/3.4.0 - Release Notes
References () https://github.com/tinymce/tinymce/security/advisories/GHSA-r8hm-w5f7-wj39 - Third Party Advisory () https://github.com/tinymce/tinymce/security/advisories/GHSA-r8hm-w5f7-wj39 - Third Party Advisory
References () https://pypi.org/project/django-tinymce/3.4.0/ - Release Notes () https://pypi.org/project/django-tinymce/3.4.0/ - Release Notes
References () https://vulncheck.com/advisories/vc-advisory-GHSA-r8hm-w5f7-wj39 - Third Party Advisory () https://vulncheck.com/advisories/vc-advisory-GHSA-r8hm-w5f7-wj39 - Third Party Advisory

08 Jan 2024, 19:46

Type Values Removed Values Added
CPE cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*
References () https://vulncheck.com/advisories/vc-advisory-GHSA-r8hm-w5f7-wj39 - () https://vulncheck.com/advisories/vc-advisory-GHSA-r8hm-w5f7-wj39 - Third Party Advisory
References () https://github.com/jazzband/django-tinymce/issues/366 - () https://github.com/jazzband/django-tinymce/issues/366 - Issue Tracking, Third Party Advisory
References () https://pypi.org/project/django-tinymce/3.4.0/ - () https://pypi.org/project/django-tinymce/3.4.0/ - Release Notes
References () https://github.com/advisories/GHSA-r8hm-w5f7-wj39 - () https://github.com/advisories/GHSA-r8hm-w5f7-wj39 - Exploit, Third Party Advisory
References () https://github.com/tinymce/tinymce/security/advisories/GHSA-r8hm-w5f7-wj39 - () https://github.com/tinymce/tinymce/security/advisories/GHSA-r8hm-w5f7-wj39 - Third Party Advisory
References () https://github.com/jazzband/django-tinymce/releases/tag/3.4.0 - () https://github.com/jazzband/django-tinymce/releases/tag/3.4.0 - Release Notes
First Time Tiny
Tiny tinymce
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

03 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-03 16:15

Updated : 2025-11-28 16:15


NVD link : CVE-2024-21910

Mitre link : CVE-2024-21910

CVE.ORG link : CVE-2024-21910


JSON object : View

Products Affected

tiny

  • tinymce
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')