CVE-2023-48219

Special characters in unescaped text nodes can trigger mXSS in TinyMCE

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not escaped upon serialization according to the HTML standard. If such text nodes contain a special character reserved as an internal marker, they can be combined with other HTML patterns to form malicious snippets. These snippets pass the initial sanitisation layer when the content is parsed into the editor body, but can trigger XSS when the special internal marker is removed from the content and re-parsed. his vulnerability has been patched in TinyMCE versions 6.7.3 and 5.10.9. Users are advised to upgrade. There are no known workarounds for this vulnerability.


We have discovered 12,214 live websites that are affected by CVE-2023-48219.

Run a Free Instant Scan




Affected Software

Product  TinyMCE
Category Rich Text Editors
Vulnerable Domains12,214 live websites (100% of TinyMCE install base)
Vulnerable Versions
  • from 0 through 5.10.9
  • from 6 through 6.7.3
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 15, 2023
  • Updated - Aug 29, 2024

Website Distribution by Country

Number of websites using CVE-2023-48219
United States6,982 websites



Germany825 websites
Denmark403 websites
Sweden340 websites
France333 websites
China314 websites
Poland293 websites
Netherlands264 websites
Spain262 websites
GB249 websites

Website Distribution by TLD

Number of websites using CVE-2023-48219
.com6,209 websites
.org675 websites
.dk582 websites
.de495 websites
.net443 websites
.se319 websites
.pl255 websites
.nl233 websites
.es201 websites
.ca158 websites

Websites affected by CVE-2023-48219

Top websites that are affected by CVE-2023-48219. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.******.de Germany*,***
*****************.com United States**,***
**********.com United States**,***
******.fr United States**,***
***********.*****.com China**,***
***********.com United States**,***
***.************.com Canada**,***
*************.com United States**,***
******.de Germany**,***
*******.com United States**,***
See full domain list

FAQ

CVE-2023-48219 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TinyMCE
A total of 12,214 websites have been identified as vulnerable to CVE-2023-48219, based on global website indexing conducted by WebTechSurvey.
The TinyMCE is affected by the CVE-2023-48219 vulnerability.
TinyMCE versions up to 6.7.3 are vulnerable to CVE-2023-48219.
CVE-2023-48219 is resolved in version 6.7.3 of TinyMCE.