CVE-2024-29203

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor. These `iframe` elements are restricted in their permissions by same-origin browser protections, but could still trigger operations such as downloading of malicious assets. This vulnerability is fixed in 6.8.1.


We have discovered 27,550 live websites that are affected by CVE-2024-29203.

Test my site




Affected Software

Product  TinyMCE
Category Rich Text Editors
Vulnerable Domains27,550 live websites (89.15% of TinyMCE install base)
Vulnerable Versions
  • from 0 before 6.8.1
Vulnerable Versions Count304 versions ( 92.12% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Mar 26, 2024
  • Updated - Aug 6, 2024

CVE-2024-29203 usage by Country

United States16,121 websites



Germany2,422 websites
France1,823 websites
Singapore1,190 websites
Netherlands744 websites
GB588 websites
China366 websites
Poland334 websites
Italy292 websites
Spain262 websites

CVE-2024-29203 usage by TLD

.com14,306 websites
.org1,506 websites
.de1,168 websites
.fr993 websites
.io823 websites
.net764 websites
.nl734 websites
.dk625 websites
.co.uk598 websites
.ca357 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-29203

Top websites that are affected by CVE-2024-29203. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Germany*,***
****.******.de United States*,***
*******.com United States*,***
********.*********.com United States*,***
*******.com United States*,***
******.io Singapore*,***
*****************.com United States**,***
**********.com United States**,***
*************.com United States**,***
***************.com United States**,***
See full domain list

FAQ

CVE-2024-29203 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TinyMCE
A total of 27,550 websites have been identified as vulnerable to CVE-2024-29203, discovered through global website indexing conducted by WebTechSurvey.
TinyMCE is susceptible to CVE-2024-29203 vulnerability.
TinyMCE versions before 6.8.1 are vulnerable to CVE-2024-29203.
Version 6.8.1 of TinyMCE addresses the CVE-2024-29203 security vulnerability.