CVE-2024-29881

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could potentially contain a XSS payload. This vulnerability is fixed in 6.8.1 and 7.0.0.


We have discovered 29,872 live websites that are affected by CVE-2024-29881.

Test my site




Affected Software

Product  TinyMCE
Category Rich Text Editors
Vulnerable Domains29,872 live websites (96.67% of TinyMCE install base)
Vulnerable Versions
  • from 0 before 7
Vulnerable Versions Count310 versions ( 93.94% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Mar 26, 2024
  • Updated - Aug 2, 2024

CVE-2024-29881 usage by Country

United States18,249 websites



Germany2,489 websites
France1,827 websites
Singapore1,190 websites
Netherlands753 websites
GB593 websites
China368 websites
Poland339 websites
Italy293 websites
Spain266 websites

CVE-2024-29881 usage by TLD

.com15,665 websites
.org2,063 websites
.de1,200 websites
.fr996 websites
.net892 websites
.io824 websites
.nl782 websites
.dk629 websites
.co.uk603 websites
.ca368 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-29881

Top websites that are affected by CVE-2024-29881. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Germany*,***
****.******.de United States*,***
*******.com United States*,***
********.*********.com United States*,***
*******.com United States*,***
******.io Singapore*,***
*****************.com United States**,***
**********.com United States**,***
*************.com United States**,***
***************.com United States**,***
See full domain list

FAQ

CVE-2024-29881 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in TinyMCE
A total of 29,872 websites have been identified as vulnerable to CVE-2024-29881, discovered through global website indexing conducted by WebTechSurvey.
TinyMCE is susceptible to CVE-2024-29881 vulnerability.
TinyMCE versions before 7 are vulnerable to CVE-2024-29881.
Version 7 of TinyMCE addresses the CVE-2024-29881 security vulnerability.