Package Health

tinymce

Web based JavaScript HTML WYSIWYG editor control.

Latest 8.9.3NPMNPM

86%

Total Score

healthy

Regular releases and broad contribution keep TinyMCE healthy, despite unpinned workflow actions and stalled pull-request activity.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

The release uses staged publishing with a GitHub trusted publisher identity, but it has no attestation. Staged publishing is a compensating control, leaving only a modest transparency gap.

Repo issue activitycaution

The repository received six new issues in the last month but closed no issues and merged no pull requests. The lack of recent resolution is a maintenance caution, though it is outweighed by active commits and releases.

Workflow auditcaution

The single workflow was fully analyzed with no audit findings, no untrusted checkouts, and job-level permissions. However, all four action references are unpinned, which weakens reproducibility and supply-chain hygiene.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-47761
tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0 - 5.10.9 and 0 - 5.10.9.
0 - 5.10.96.0.0 - 7.9.38.0.0 - 8.5.1
High
CVE-2026-47762
tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0.0.0 - 5.10.9 and 0.0.0 - 5.10.9.
0.0.0 - 5.10.96.0.0 - 7.9.38.0.0 - 8.5.1
High
CVE-2026-47759
tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 6.0.0 - 7.9.3, 8.0.0 - 8.5.1, 0.0.0 - 5.10.9 and 0.0.0 - 5.10.9.
0.0.0 - 5.10.96.0.0 - 7.9.38.0.0 - 8.5.1
High
CVE-2026-47760
tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.8.0 - 7.1.0 and 6.8.0 - 7.1.0.
6.8.0 - 7.1.0
High
CVE-2024-38357
tinymce is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.11.0, 0.0.0 - 5.11.0, 6.0.0 - 6.8.4, 7.0.0 - 7.2.0, 6.0.0 - 6.8.4 and 7.0.0 - 7.2.0.
0.0.0 - 5.11.06.0.0 - 6.8.47.0.0 - 7.2.0
Medium

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 days ago
Created
12 years ago
Unpacked Size
11.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform