Skip to content
Noroxi

Tiny records

21 published records for vendor tiny.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 4.8%
Pre-auth RCE
0
With a fix record
81%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 20
  3. 21
  4. 22
  5. 23
  6. 24
  7. 26

Bar: total · dark part: CISA KEV.

All records

21 records
  • TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

    CriticalCVSS 9.8WeaponizedEPSS 56%

    tiny · tinybrowserFeb 12, 2020

  • Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

    CriticalCVSS 9.8Proof of conceptEPSS 10%

    tiny · tinybrowserFeb 12, 2020

  • Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 1%

    tiny · pluploadDec 3, 2021

  • WordPress Setka Editor Plugin <= 2.1.20 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    tiny · setka workflowFeb 28, 2024

  • Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a

    HighCVSS 7.5No exploitEPSS 2%

    jenzabar · internet campus solutionMar 25, 2019

  • tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation.

    MediumCVSS 6.1No exploitEPSS 2%

    tiny · tinymceJul 17, 2019

  • A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configur

    MediumCVSS 6.1No exploitEPSS 2%

    tiny · tinymceAug 14, 2020

  • TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceAug 10, 2020

  • Cross-site scripting vulnerability in TinyMCE

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceJan 3, 2024

  • Cross-site scripting vulnerability in TinyMCE

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceJan 3, 2024

  • Cross-site scripting vulnerability in TinyMCE alerts

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceDec 8, 2022

  • Cross-site scripting vulnerability in TinyMCE plugins

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceJan 3, 2024

  • Special characters in unescaped text nodes can trigger mXSS in TinyMCE

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceNov 15, 2023

  • TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceMar 26, 2024

  • TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceMar 26, 2024

  • Cross-site Scripting vulnerability in TinyMCE undo/redo, getContent API, resetContent API, and Autosave plugin

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceOct 19, 2023

  • Cross-site Scripting vulnerability in TinyMCE notificationManager.open API

    MediumCVSS 6.1No exploitEPSS 1%

    tiny · tinymceOct 19, 2023

  • TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

    MediumCVSS 5.4No exploitEPSS 0%

    tiny · tinymceMay 28, 2026

  • TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

    MediumCVSS 5.4No exploitEPSS 0%

    tiny · tinymceMay 28, 2026

  • TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection

    MediumCVSS 5.4Proof of conceptEPSS 0%

    tiny · tinymceMay 28, 2026

  • TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

    MediumCVSS 5.4No exploitEPSS 0%

    tiny · tinymceMay 28, 2026