CVE-2022-23494

Cross-site scripting vulnerability in TinyMCE alerts

tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confirm dialogs, such as in the `image` plugin, which presents these dialogs when certain errors occur. The vulnerability allowed arbitrary JavaScript execution when an alert presented in the TinyMCE UI for the current user. This vulnerability has been patched in TinyMCE 5.10.7 and TinyMCE 6.3.1 by ensuring HTML sanitization was still performed after unwrapping invalid elements. Users are advised to upgrade to either 5.10.7 or 6.3.1. Users unable to upgrade may ensure the the `images_upload_handler` returns a valid value as per the images_upload_handler documentation.


We have discovered 11,688 live websites that are affected by CVE-2022-23494.

Test my site




Affected Software

Product  TinyMCE
Category Rich Text Editors
Vulnerable Domains11,688 live websites (37.82% of TinyMCE install base)
Vulnerable Versions
  • from 0 before 5.10.7
  • from 6 before 6.3.1
Vulnerable Versions Count270 versions ( 81.82% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 8, 2022
  • Updated - Aug 3, 2024

CVE-2022-23494 usage by Country

United States7,575 websites



Germany1,066 websites
France340 websites
China308 websites
Singapore302 websites
Poland237 websites
Netherlands179 websites
Spain155 websites
Hungary146 websites
GB146 websites

CVE-2022-23494 usage by TLD

.com6,483 websites
.org694 websites
.dk565 websites
.de480 websites
.net434 websites
.pl226 websites
.at158 websites
.nl157 websites
.ca149 websites
.co.uk130 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-23494

Top websites that are affected by CVE-2022-23494. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.******.de United States*,***
*****************.com United States**,***
**********.com United States**,***
***********.com United States**,***
***.************.com Canada**,***
************.com United States**,***
*******.com United States**,***
*********.*******.com United States**,***
*****.*******.io United States**,***
******.com United States**,***
See full domain list

FAQ

CVE-2022-23494 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TinyMCE
A total of 11,688 websites have been identified as vulnerable to CVE-2022-23494, discovered through global website indexing conducted by WebTechSurvey.
TinyMCE is susceptible to CVE-2022-23494 vulnerability.
TinyMCE versions before 6.3.1 are vulnerable to CVE-2022-23494.
Version 6.3.1 of TinyMCE addresses the CVE-2022-23494 security vulnerability.