tinymce@6.2.0 vulnerabilities

Web based JavaScript HTML WYSIWYG editor control.

Direct Vulnerabilities

Known vulnerabilities in the tinymce package. This does not include vulnerabilities belonging to this package’s dependencies.

Cross-site Scripting (XSS)

tinymce is a web-based JavaScript HTML WYSIWYG editor control.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confirm dialogs, such as in the image plugin, which presents these dialogs when certain errors occur.

How to fix Cross-site Scripting (XSS)?

Upgrade tinymce to version 5.10.7, 6.3.1 or higher.

<5.10.7 >=6.0.0 <6.3.1