Description
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Remediation
References
https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95
https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes
Related Vulnerabilities
CVE-2022-0839 Vulnerability in maven package org.liquibase:liquibase-core
CVE-2022-0686 Vulnerability in npm package url-parse
CVE-2022-39366 Vulnerability in maven package io.acryl:datahub-client
CVE-2022-25872 Vulnerability in npm package fast-string-search
CVE-2019-17495 Vulnerability in maven package org.webjars.bower:swagger-ui