Description
TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
Remediation
References
Related Vulnerabilities
Liferay DXP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-25143)
WordPress Plugin SG Optimizer Multiple Vulnerabilities (3.3.5)
WordPress Plugin Disable Feeds Unspecified Vulnerability (1.4)
PHP Improper Input Validation Vulnerability (CVE-2007-4840)
WordPress Plugin Poll, Survey, Form & Quiz Maker by OpinionStage Unspecified Vulnerability (15.0.0)