{"id":"CVE-2024-38356","aliases":["GHSA-9hcv-j9pv-qmph","PYSEC-2026-1301"],"url":"https://o3.security/vulnerability/CVE-2024-38356","summary":"TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option","details":"### Impact\nA [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor.\n\n### Patches\nThis vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that, when using the `noneditable_regexp` option, any content within an attribute is properly verified to match the configured regular expression before being added.\n\n### Fix\nTo avoid this vulnerability:\n\n* Upgrade to TinyMCE 7.2.0 or higher.\n* Upgrade to TinyMCE 6.8.4 or higher for TinyMCE 6.x.\n* Upgrade to TinyMCE 5.11.0 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract).\n\n### References\n* [TinyMCE 6.8.4](https://www.tiny.cloud/docs/tinymce/6/6.8.4-release-notes/#overview)\n* [TinyMCE 7.2.0](https://www.tiny.cloud/docs/tinymce/7/7.2-release-notes/#overview)\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Email us at [infosec@tiny.cloud](mailto:infosec@tiny.cloud)\n* Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues?q=is%3Aissue+is%3Aopen+sort%3Aupdated-desc)","published":"2024-06-19T20:03:47.923Z","modified":"2026-08-12T03:51:22.940736958Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00529,"percentile":0.43528,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"tinymce","fixedVersion":"5.11.0"},{"ecosystem":"npm","name":"tinymce","fixedVersion":"6.8.4"},{"ecosystem":"npm","name":"tinymce","fixedVersion":"7.2.0"},{"ecosystem":"NuGet","name":"TinyMCE","fixedVersion":"5.11.0"},{"ecosystem":"NuGet","name":"TinyMCE","fixedVersion":"6.8.4"},{"ecosystem":"NuGet","name":"TinyMCE","fixedVersion":"7.2.0"},{"ecosystem":"Packagist","name":"tinymce/tinymce","fixedVersion":"5.11.0"},{"ecosystem":"Packagist","name":"tinymce/tinymce","fixedVersion":"6.8.4"},{"ecosystem":"Packagist","name":"tinymce/tinymce","fixedVersion":"7.2.0"},{"ecosystem":"PyPI","name":"django-tinymce","fixedVersion":"4.1.0"}],"fix":{"url":"https://github.com/tinymce/tinymce/commit/5acb741665a98e83d62b91713c800abbff43b00d","label":"tinymce/tinymce@5acb741"},"references":[{"type":"WEB","url":"https://owasp.org/www-community/attacks/xss"},{"type":"WEB","url":"https://www.tiny.cloud/docs/tinymce/6/6.8.4-release-notes/#overview"},{"type":"WEB","url":"https://www.tiny.cloud/docs/tinymce/7/7.2-release-notes/#overview"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38356.json"},{"type":"ADVISORY","url":"https://github.com/tinymce/tinymce/security/advisories/GHSA-9hcv-j9pv-qmph"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38356"},{"type":"FIX","url":"https://github.com/tinymce/tinymce/commit/5acb741665a98e83d62b91713c800abbff43b00d"},{"type":"WEB","url":"https://github.com/tinymce/tinymce/commit/a9fb858509f86dacfa8b01cfd34653b408983ac0"},{"type":"PACKAGE","url":"https://github.com/tinymce/tinymce"},{"type":"WEB","url":"https://www.tiny.cloud/docs/tinymce/latest/7.2-release-notes/#overview"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.940736958Z"}}