TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could potentially contain a XSS payload. This vulnerability is fixed in 6.8.1 and 7.0.0.
We have discovered 28,104 live websites that are affected by CVE-2024-29881.
| Product | |
| Category | Rich Text Editors |
| Vulnerable Domains | 28,104 live websites (100% of TinyMCE install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 15,608 websites | |
| 1,903 websites | |
| 1,600 websites | |
| 885 websites | |
| 834 websites | |
| 761 websites | |
| 503 websites | |
| 480 websites | |
| 466 websites | |
| 426 websites |
| .com | 14,247 websites |
| .org | 1,916 websites |
| .de | 1,165 websites |
| .net | 1,060 websites |
| .fr | 912 websites |
| .io | 807 websites |
| .nl | 675 websites |
| .dk | 631 websites |
| .co.uk | 543 websites |
| .se | 397 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | *,*** | ||
| ****.******.de | *,*** | ||
| *******.com | *,*** | ||
| ********.*********.com | *,*** | ||
| *******.com | *,*** | ||
| ******.io | *,*** | ||
| *****************.com | **,*** | ||
| **********.com | **,*** | ||
| *************.com | **,*** | ||
| ***************.com | **,*** |
FAQ