CVE-2024-21910

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/01/2024
Last modified:
28/11/2025

Description

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:* 5.10.0 (excluding)