TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could potentially contain a XSS payload. This vulnerability is fixed in 6.8.1 and 7.0.0.
We have discovered 29,872 live websites that are affected by CVE-2024-29881.
Product | ![]() |
Category | Rich Text Editors |
Vulnerable Domains | 29,872 live websites (96.67% of TinyMCE install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 310 versions ( 93.94% of all versions) |
![]() | 18,249 websites |
![]() | 2,489 websites |
![]() | 1,827 websites |
![]() | 1,190 websites |
![]() | 753 websites |
![]() | 593 websites |
![]() | 368 websites |
![]() | 339 websites |
![]() | 293 websites |
![]() | 266 websites |
.com | 15,665 websites |
.org | 2,063 websites |
.de | 1,200 websites |
.fr | 996 websites |
.net | 892 websites |
.io | 824 websites |
.nl | 782 websites |
.dk | 629 websites |
.co.uk | 603 websites |
.ca | 368 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *,*** | |
****.******.de | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
********.*********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
******.io | ![]() | *,*** | |
*****************.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***************.com | ![]() | **,*** |
FAQ