Description
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Remediation
References
https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95
https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes
Related Vulnerabilities
CVE-2021-29451 Vulnerability in maven package com.manydesigns:portofino-core
CVE-2021-32809 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2020-28502 Vulnerability in maven package org.webjars.npm:xmlhttprequest-ssl
CVE-2023-22461 Vulnerability in npm package @mattkrick/sanitize-svg
CVE-2023-46659 Vulnerability in maven package org.jenkins-ci.plugins:trac