CVE-2023-48219

Special characters in unescaped text nodes can trigger mXSS in TinyMCE

TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not escaped upon serialization according to the HTML standard. If such text nodes contain a special character reserved as an internal marker, they can be combined with other HTML patterns to form malicious snippets. These snippets pass the initial sanitisation layer when the content is parsed into the editor body, but can trigger XSS when the special internal marker is removed from the content and re-parsed. his vulnerability has been patched in TinyMCE versions 6.7.3 and 5.10.9. Users are advised to upgrade. There are no known workarounds for this vulnerability.


We have discovered 26,637 live websites that are affected by CVE-2023-48219.

Test my site




Affected Software

Product  TinyMCE
Category Rich Text Editors
Vulnerable Domains26,637 live websites (86.20% of TinyMCE install base)
Vulnerable Versions
  • from 0 before 5.10.9
  • from 6 before 6.7.3
Vulnerable Versions Count296 versions ( 89.70% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 15, 2023
  • Updated - Aug 29, 2024

CVE-2023-48219 usage by Country

United States16,059 websites



Germany2,414 websites
France1,822 websites
Netherlands738 websites
GB575 websites
Singapore381 websites
China365 websites
Poland333 websites
Italy292 websites
Spain261 websites

CVE-2023-48219 usage by TLD

.com14,265 websites
.org1,453 websites
.de1,166 websites
.fr991 websites
.net763 websites
.nl715 websites
.dk625 websites
.co.uk592 websites
.ca356 websites
.be343 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-48219

Top websites that are affected by CVE-2023-48219. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Germany*,***
****.******.de United States*,***
*******.com United States*,***
********.*********.com United States*,***
*******.com United States*,***
*****************.com United States**,***
**********.com United States**,***
*************.com United States**,***
***************.com United States**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2023-48219 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TinyMCE
A total of 26,637 websites have been identified as vulnerable to CVE-2023-48219, discovered through global website indexing conducted by WebTechSurvey.
TinyMCE is susceptible to CVE-2023-48219 vulnerability.
TinyMCE versions before 6.7.3 are vulnerable to CVE-2023-48219.
Version 6.7.3 of TinyMCE addresses the CVE-2023-48219 security vulnerability.