CVE-2024-29881

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could potentially contain a XSS payload. This vulnerability is fixed in 6.8.1 and 7.0.0.


We have discovered 28,104 live websites that are affected by CVE-2024-29881.

Run a Free Instant Scan




Affected Software

Product  TinyMCE
Category Rich Text Editors
Vulnerable Domains28,104 live websites (100% of TinyMCE install base)
Vulnerable Versions
  • from 0 through 7
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Mar 26, 2024
  • Updated - Aug 2, 2024

Website Distribution by Country

Number of websites using CVE-2024-29881
United States15,608 websites



Germany1,903 websites
France1,600 websites
Singapore885 websites
GB834 websites
Netherlands761 websites
Canada503 websites
Italy480 websites
Denmark466 websites
Sweden426 websites

Website Distribution by TLD

Number of websites using CVE-2024-29881
.com14,247 websites
.org1,916 websites
.de1,165 websites
.net1,060 websites
.fr912 websites
.io807 websites
.nl675 websites
.dk631 websites
.co.uk543 websites
.se397 websites

Websites affected by CVE-2024-29881

Top websites that are affected by CVE-2024-29881. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
****.******.de Germany*,***
*******.com United States*,***
********.*********.com United States*,***
*******.com United States*,***
******.io Singapore*,***
*****************.com United States**,***
**********.com United States**,***
*************.com United States**,***
***************.com United States**,***
See full domain list

FAQ

CVE-2024-29881 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TinyMCE
A total of 28,104 websites have been identified as vulnerable to CVE-2024-29881, based on global website indexing conducted by WebTechSurvey.
The TinyMCE is affected by the CVE-2024-29881 vulnerability.
TinyMCE versions up to 7 are vulnerable to CVE-2024-29881.
CVE-2024-29881 is resolved in version 7 of TinyMCE.