Description
TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
Remediation
References
Related Vulnerabilities
MyBB Other Vulnerability (CVE-2007-0689)
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2019-18838)
WordPress Plugin Collision Testimonials 'admin.php' SQL Injection (3.0)
WordPress Plugin Easy Registration Forms Cross-Site Scripting (1.8.3)
Atlassian Jira CVE-2019-20402 Vulnerability (CVE-2019-20402)