CVE-2022-23494

Cross-site scripting vulnerability in TinyMCE alerts

tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confirm dialogs, such as in the `image` plugin, which presents these dialogs when certain errors occur. The vulnerability allowed arbitrary JavaScript execution when an alert presented in the TinyMCE UI for the current user. This vulnerability has been patched in TinyMCE 5.10.7 and TinyMCE 6.3.1 by ensuring HTML sanitization was still performed after unwrapping invalid elements. Users are advised to upgrade to either 5.10.7 or 6.3.1. Users unable to upgrade may ensure the the `images_upload_handler` returns a valid value as per the images_upload_handler documentation.


We have discovered 10,411 live websites that are affected by CVE-2022-23494.

Run a Free Instant Scan




Affected Software

Product  TinyMCE
Category Rich Text Editors
Vulnerable Domains10,411 live websites (100% of TinyMCE install base)
Vulnerable Versions
  • from 0 through 5.10.7
  • from 6 through 6.3.1
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 8, 2022
  • Updated - Apr 23, 2025

Website Distribution by Country

Number of websites using CVE-2022-23494
United States6,270 websites



Germany678 websites
Denmark392 websites
Sweden333 websites
China293 websites
Poland247 websites
Spain226 websites
France203 websites
GB179 websites
Canada172 websites

Website Distribution by TLD

Number of websites using CVE-2022-23494
.com5,420 websites
.org589 websites
.dk574 websites
.de422 websites
.net403 websites
.se314 websites
.pl223 websites
.es181 websites
.ca133 websites
.nl132 websites

Websites affected by CVE-2022-23494

Top websites that are affected by CVE-2022-23494. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.******.de Germany*,***
*****************.com United States**,***
**********.com United States**,***
***********.*****.com China**,***
***********.com United States**,***
***.************.com Canada**,***
*******.com United States**,***
*****.*******.io United States**,***
*********.net United States**,***
*********.com United States**,***
See full domain list

FAQ

CVE-2022-23494 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TinyMCE
A total of 10,411 websites have been identified as vulnerable to CVE-2022-23494, based on global website indexing conducted by WebTechSurvey.
The TinyMCE is affected by the CVE-2022-23494 vulnerability.
TinyMCE versions up to 6.3.1 are vulnerable to CVE-2022-23494.
CVE-2022-23494 is resolved in version 6.3.1 of TinyMCE.