Description
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Remediation
References
https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95
https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes
Related Vulnerabilities
CVE-2021-21306 Vulnerability in npm package marked
CVE-2022-31160 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui
CVE-2022-0401 Vulnerability in npm package w-zip
CVE-2019-10742 Vulnerability in maven package org.webjars.npm:axios
CVE-2023-46998 Vulnerability in maven package org.webjars.npm:bootbox.js