CVE-2024-29203

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor. These `iframe` elements are restricted in their permissions by same-origin browser protections, but could still trigger operations such as downloading of malicious assets. This vulnerability is fixed in 6.8.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*
cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*

History

02 Sep 2025, 16:20

Type Values Removed Values Added
First Time Tiny
Tiny tinymce
CPE cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*
References () https://github.com/tinymce/tinymce/commit/bcdea2ad14e3c2cea40743fb48c63bba067ae6d1 - () https://github.com/tinymce/tinymce/commit/bcdea2ad14e3c2cea40743fb48c63bba067ae6d1 - Patch
References () https://github.com/tinymce/tinymce/security/advisories/GHSA-438c-3975-5x3f - () https://github.com/tinymce/tinymce/security/advisories/GHSA-438c-3975-5x3f - Vendor Advisory
References () https://www.tiny.cloud/docs/tinymce/6/6.8.1-release-notes/#new-convert_unsafe_embeds-option-that-controls-whether-object-and-embed-elements-will-be-converted-to-more-restrictive-alternatives-namely-img-for-image-mime-types-video-for-video-mime-types-audio-audio-mime-types-or-iframe-for-other-or-unspecified-mime-types - () https://www.tiny.cloud/docs/tinymce/6/6.8.1-release-notes/#new-convert_unsafe_embeds-option-that-controls-whether-object-and-embed-elements-will-be-converted-to-more-restrictive-alternatives-namely-img-for-image-mime-types-video-for-video-mime-types-audio-audio-mime-types-or-iframe-for-other-or-unspecified-mime-types - Release Notes
References () https://www.tiny.cloud/docs/tinymce/7/7.0-release-notes/#sandbox_iframes-editor-option-is-now-defaulted-to-true - () https://www.tiny.cloud/docs/tinymce/7/7.0-release-notes/#sandbox_iframes-editor-option-is-now-defaulted-to-true - Release Notes

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://github.com/tinymce/tinymce/commit/bcdea2ad14e3c2cea40743fb48c63bba067ae6d1 - () https://github.com/tinymce/tinymce/commit/bcdea2ad14e3c2cea40743fb48c63bba067ae6d1 -
References () https://github.com/tinymce/tinymce/security/advisories/GHSA-438c-3975-5x3f - () https://github.com/tinymce/tinymce/security/advisories/GHSA-438c-3975-5x3f -
References () https://www.tiny.cloud/docs/tinymce/6/6.8.1-release-notes/#new-convert_unsafe_embeds-option-that-controls-whether-object-and-embed-elements-will-be-converted-to-more-restrictive-alternatives-namely-img-for-image-mime-types-video-for-video-mime-types-audio-audio-mime-types-or-iframe-for-other-or-unspecified-mime-types - () https://www.tiny.cloud/docs/tinymce/6/6.8.1-release-notes/#new-convert_unsafe_embeds-option-that-controls-whether-object-and-embed-elements-will-be-converted-to-more-restrictive-alternatives-namely-img-for-image-mime-types-video-for-video-mime-types-audio-audio-mime-types-or-iframe-for-other-or-unspecified-mime-types -
References () https://www.tiny.cloud/docs/tinymce/7/7.0-release-notes/#sandbox_iframes-editor-option-is-now-defaulted-to-true - () https://www.tiny.cloud/docs/tinymce/7/7.0-release-notes/#sandbox_iframes-editor-option-is-now-defaulted-to-true -
Summary
  • (es) TinyMCE es un editor de texto enriquecido de código abierto. Se descubrió una vulnerabilidad de cross-site scripting (XSS) en el código de inserción de contenido de TinyMCE. Esto permitió que se ejecutaran elementos `iframe` que contenían código malicioso cuando se insertaban en el editor. Estos elementos "iframe" tienen permisos restringidos por protecciones del navegador del mismo origen, pero aún así podrían desencadenar operaciones como la descarga de activos maliciosos. Esta vulnerabilidad se solucionó en 6.8.1.

26 Mar 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-26 14:15

Updated : 2025-09-02 16:20


NVD link : CVE-2024-29203

Mitre link : CVE-2024-29203

CVE.ORG link : CVE-2024-29203


JSON object : View

Products Affected

tiny

  • tinymce
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')