TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor. These `iframe` elements are restricted in their permissions by same-origin browser protections, but could still trigger operations such as downloading of malicious assets. This vulnerability is fixed in 6.8.1.
We have discovered 27,550 live websites that are affected by CVE-2024-29203.
Product | ![]() |
Category | Rich Text Editors |
Vulnerable Domains | 27,550 live websites (89.15% of TinyMCE install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 304 versions ( 92.12% of all versions) |
![]() | 16,121 websites |
![]() | 2,422 websites |
![]() | 1,823 websites |
![]() | 1,190 websites |
![]() | 744 websites |
![]() | 588 websites |
![]() | 366 websites |
![]() | 334 websites |
![]() | 292 websites |
![]() | 262 websites |
.com | 14,306 websites |
.org | 1,506 websites |
.de | 1,168 websites |
.fr | 993 websites |
.io | 823 websites |
.net | 764 websites |
.nl | 734 websites |
.dk | 625 websites |
.co.uk | 598 websites |
.ca | 357 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *,*** | |
****.******.de | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
********.*********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
******.io | ![]() | *,*** | |
*****************.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***************.com | ![]() | **,*** |
FAQ