Web based JavaScript HTML WYSIWYG editor control.
86%
Total Score
healthy
Regular releases and broad contribution keep TinyMCE healthy, despite unpinned workflow actions and stalled pull-request activity.
The release uses staged publishing with a GitHub trusted publisher identity, but it has no attestation. Staged publishing is a compensating control, leaving only a modest transparency gap.
The repository received six new issues in the last month but closed no issues and merged no pull requests. The lack of recent resolution is a maintenance caution, though it is outweighed by active commits and releases.
The single workflow was fully analyzed with no audit findings, no untrusted checkouts, and job-level permissions. However, all four action references are unpinned, which weakens reproducibility and supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-47761 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0 - 5.10.9 and 0 - 5.10.9. | 0 - 5.10.96.0.0 - 7.9.38.0.0 - 8.5.1 | High |
CVE-2026-47762 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0.0.0 - 5.10.9 and 0.0.0 - 5.10.9. | 0.0.0 - 5.10.96.0.0 - 7.9.38.0.0 - 8.5.1 | High |
CVE-2026-47759 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0.0.0 - 5.10.9 and 0.0.0 - 5.10.9. | 0.0.0 - 5.10.96.0.0 - 7.9.38.0.0 - 8.5.1 | High |
CVE-2026-47760 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.8.0 - 7.1.0 and 6.8.0 - 7.1.0. | 6.8.0 - 7.1.0 | High |
CVE-2024-38357 tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.11.0, 0.0.0 - 5.11.0, 6.0.0 - 6.8.4, 7.0.0 - 7.2.0, 6.0.0 - 6.8.4 and 7.0.0 - 7.2.0. | 0.0.0 - 5.11.06.0.0 - 6.8.47.0.0 - 7.2.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.