django-tinymce
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting django-tinymcepage 1 of 1
- CVE-2024-21910MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.4.02024-01-03
vulnerable: 1.0 ... 3.3.0 (44 versions)
TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing …
- CVE-2024-38356MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.1.02024-06-19
vulnerable: 1.0 ... 4.0.0 (51 versions)
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing maliciou…
- CVE-2024-38357MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.1.02024-06-19
vulnerable: 1.0 ... 4.0.0 (51 versions)
TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that …
Check whether django-tinymce is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for django-tinymce CVEs against the assets you own.
Start Free Scan →