PT-2021-24351 · Tinymce · Tinymce

Yakir6

·

Published

2021-11-02

·

Updated

2025-11-28

·

CVE-2024-21910

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: TinyMCE versions prior to 5.10.0
Description: A cross-site scripting vulnerability was discovered in the URL processing logic of the image and link plugins, allowing arbitrary JavaScript execution when updating an image or link using a specially crafted URL. This issue only impacts users while editing, and the dangerous URLs are stripped in any content extracted from the editor.
Recommendations: To resolve the issue, either:
  • Upgrade to TinyMCE 5.10.0 or higher
  • Disable the image and link plugins as a temporary workaround until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-21910
GHSA-R8HM-W5F7-WJ39
GHSA-WXJ2-777F-VXMF

Affected Products

Tinymce