Description
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Remediation
References
https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95
https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes
Related Vulnerabilities
CVE-2020-27218 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2022-29258 Vulnerability in maven package org.xwiki.platform:xwiki-platform-filter-ui
CVE-2021-33562 Vulnerability in maven package com.shopizer:shopizer
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-broker
CVE-2020-7746 Vulnerability in maven package org.webjars.bowergithub.chartjs:chart.js