Skip to content
Noroxi

tinymce records

7 published records for vendor tinymce.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 14.3%
Pre-auth RCE
1
With a fix record
42.9%
Median publish → KEV
No record has entered KEV

All records

7 records
  • Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, php

    HighCVSS 7.5WeaponizedEPSS 39%

    tinymce · tinymceDec 14, 2011

  • CVE-2014-3845
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijac

    MediumCVSS 6.8No exploitEPSS 1%

    tinymce · color pickerMay 22, 2014

  • CVE-2012-6112
    21Monitor

    classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2

    MediumCVSS 5.0No exploitEPSS 2%

    tinymce · spellchecker phpJan 27, 2013

  • CVE-2014-3844
    21Monitor

    The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin

    MediumCVSS 5.0No exploitEPSS 2%

    tinymce · color pickerMay 22, 2014

  • CVE-2012-3414
    20Monitor

    Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image

    MediumCVSS 4.3Proof of conceptEPSS 9%

    tinymce · image managerJul 19, 2013

  • CVE-2013-2204
    18Monitor

    moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider

    MediumCVSS 4.3No exploitEPSS 3%

    tinymce · mediaJul 8, 2013

  • CVE-2012-4230
    17Monitor

    The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elemen

    MediumCVSS 4.3No exploitEPSS 1%

    tinymce · tinymceApr 25, 2014