latest non vulnerable version
9 years ago
latest version published
4 days ago
Known vulnerabilities in the tinymce package. This does not include vulnerabilities belonging to this package’s dependencies.Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confirm dialogs, such as in the
How to fix Cross-site Scripting (XSS)?
<5.10.7 >=6.0.0 <6.3.1