Description
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Remediation
References
https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95
https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes
Related Vulnerabilities
CVE-2022-25854 Vulnerability in npm package @yaireo/tagify
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.diguoyihao:layui
CVE-2023-40346 Vulnerability in maven package io.jenkins.plugins:shortcut-job
CVE-2021-46708 Vulnerability in npm package swagger-ui-dist
CVE-2022-21802 Vulnerability in maven package org.webjars.npm:grapesjs