TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
We have discovered 10,006 live websites that are affected by CVE-2024-21911.
Product | ![]() |
Category | Rich Text Editors |
Vulnerable Domains | 10,006 live websites (32.38% of TinyMCE install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 206 versions ( 62.42% of all versions) |
![]() | 6,863 websites |
![]() | 770 websites |
![]() | 294 websites |
![]() | 284 websites |
![]() | 250 websites |
![]() | 155 websites |
![]() | 141 websites |
![]() | 141 websites |
![]() | 91 websites |
![]() | 88 websites |
.com | 5,784 websites |
.org | 601 websites |
.dk | 559 websites |
.net | 382 websites |
.de | 314 websites |
.pl | 146 websites |
.ca | 137 websites |
.es | 114 websites |
.co.uk | 97 websites |
.eu | 91 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*********.*******.com | ![]() | **,*** | |
*****.*******.io | ![]() | **,*** | |
******.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
*********.*******.com | ![]() | ***,*** | |
******************.org | ![]() | ***,*** | |
***********.******.io | ![]() | ***,*** | |
*******.********.edu | ![]() | ***,*** |
FAQ