Web based JavaScript HTML WYSIWYG editor control.
84%
Total Score
70
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-47761 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.11.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0.0.0 - 5.11.1, 6.0.0 - 7.9.3 and 8.0.0 - 8.5.1. | 0.0.0 - 5.11.16.0.0 - 7.9.38.0.0 - 8.5.1 | |
CVE-2026-47762 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.11.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0.0.0 - 5.11.1, 6.0.0 - 7.9.3 and 8.0.0 - 8.5.1. | 0.0.0 - 5.11.16.0.0 - 7.9.38.0.0 - 8.5.1 | |
CVE-2026-47759 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.11.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0.0.0 - 5.11.1, 6.0.0 - 7.9.3 and 8.0.0 - 8.5.1. | 0.0.0 - 5.11.16.0.0 - 7.9.38.0.0 - 8.5.1 | |
CVE-2026-47760 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.8.0 - 7.1.0 and 6.8.0 - 7.1.0. | 6.8.0 - 7.1.0 | |
CVE-2024-38357 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.11.0, 0.0.0 - 5.11.0, 6.0.0 - 6.8.4, 7.0.0 - 7.2.0, 6.0.0 - 6.8.4 and 7.0.0 - 7.2.0. | 0.0.0 - 5.11.06.0.0 - 6.8.47.0.0 - 7.2.0 |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant