Description
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Remediation
References
https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95
https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes
Related Vulnerabilities
CVE-2018-17960 Vulnerability in maven package org.webjars.npm:ckeditor
CVE-2021-23327 Vulnerability in maven package org.webjars.npm:apexcharts
CVE-2021-23497 Vulnerability in npm package @strikeentco/set
CVE-2016-10735 Vulnerability in npm package bootstrap-sass
CVE-2023-28155 Vulnerability in maven package org.webjars.npm:request